2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39495 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in BoldThemes Avantage avantage allows Object Injection.This issue affec... |
| CVE-2025-39494 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39490 | HIGH | 8.1 | 0.5% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39489 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | Incorrect Privilege Assignment vulnerability in pebas CouponXL couponxl allows Privilege Escalation.This issue affects C... |
| CVE-2025-39485 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour grandtour allows Object Injection.This issue af... |
| CVE-2025-39480 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in ThemeMakers Car Dealer cardealer allows Object Injection.This issue a... |
| CVE-2025-32309 | HIGH | 8.1 | 0.5% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32302 | HIGH | 8.1 | 0.5% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32294 | HIGH | 8.1 | 0.5% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32293 | HIGH | 8.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in designthemes Finance Consultant finance allows Object Injection.This ... |
| CVE-2025-32292 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in AncoraThemes Jarvis – Night Club, Concert, Festival WordPress jarvis ... |
| CVE-2025-32289 | HIGH | 8.1 | 0.5% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32286 | HIGH | 8.1 | 0.5% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32285 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ApusTheme Butcher ... |
| CVE-2025-32284 | HIGH | 8.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in designthemes Pet World petsworld allows Object Injection.This issue a... |
| CVE-2025-31927 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in themeton Acerola allows Object Injection. This issue affects Acerola:... |
| CVE-2025-31924 | HIGH | 8.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in designthemes Crafts & Arts crafts-and-arts allows Object Injection.Th... |
| CVE-2025-31918 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro... |
| CVE-2025-31916 | CRITICAL | 9 | 0.4% | May 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in joy2012bd JP Students Result Management System Premium ... |
| CVE-2025-31914 | CRITICAL | 9.3 | 0.4% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Pixel... |
| CVE-2025-31913 | HIGH | 8.1 | 0.5% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-31912 | HIGH | 8.1 | 0.5% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-31636 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SaurabhSharma WP P... |
| CVE-2025-31633 | HIGH | 8.1 | 0.5% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-31632 | HIGH | 8.1 | 0.5% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now