2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46468 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-46463 | HIGH | 8.5 | 0.3% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yamna Khawaja Mail... |
| CVE-2025-46460 | CRITICAL | 9.3 | 0.4% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Detheme Easy Guide... |
| CVE-2025-46458 | HIGH | 8.2 | 0.2% | May 23, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in x000x occupancyplan occupancyplan allows SQL Injection.This issue aff... |
| CVE-2025-46456 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason Theme Blvd S... |
| CVE-2025-46455 | CRITICAL | 9.3 | 0.4% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in IndigoThemes WP HR... |
| CVE-2025-46454 | HIGH | 7.5 | 0.6% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-46448 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reifsnyderb Docume... |
| CVE-2025-46446 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ivanrojas Libro de... |
| CVE-2025-46444 | HIGH | 8.1 | 0.5% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-46440 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark kStats Reload... |
| CVE-2025-46437 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tayoricom Tayori F... |
| CVE-2025-41380 | MEDIUM | 6.1 | 0.1% | May 23, 2025 | Iridium Certus 700 version 1.0.1 has an embedded credentials vulnerability in the code. This vulnerability allows a loca... |
| CVE-2025-41379 | MEDIUM | 6.3 | 0.4% | May 23, 2025 | The Intellian C700 web panel allows you to add firewall rules. Each of these rules has an associated ID, but there is a ... |
| CVE-2025-41378 | MEDIUM | 6.9 | 0.2% | May 23, 2025 | The SSID field is not parsed correctly and can be used to inject commands into the hostpad.conf file. This can be exploi... |
| CVE-2025-41377 | HIGH | 8.7 | 0.3% | May 23, 2025 | A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The... |
| CVE-2025-39536 | HIGH | 8.2 | 0.3% | May 23, 2025 | Missing Authorization vulnerability in Chimpstudio JobHunt Job Alerts allows Exploiting Incorrectly Configured Access Co... |
| CVE-2025-39506 | HIGH | 8.1 | 0.5% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39505 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoodLayers Goodlay... |
| CVE-2025-39504 | CRITICAL | 9.3 | 0.4% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GoodLayers Goodlay... |
| CVE-2025-39503 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in GoodLayers Goodlayers Hotel gdlr-hotel allows Object Injection.This i... |
| CVE-2025-39502 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoodLayers Goodlay... |
| CVE-2025-39501 | CRITICAL | 9.3 | 0.4% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GoodLayers Goodlay... |
| CVE-2025-39500 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in GoodLayers Goodlayers Hostel gdlr-hostel allows Object Injection.This... |
| CVE-2025-39499 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in BoldThemes Medicare medicare allows Object Injection.This issue affec... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now