2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31631 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in AncoraThemes Fish House fish-house allows Object Injection.This issue... |
| CVE-2025-31430 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in themeton The Business allows Object Injection. This issue affects The... |
| CVE-2025-31423 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in AncoraThemes Umberto umberto allows Object Injection.This issue affec... |
| CVE-2025-31397 | CRITICAL | 9.3 | 0.4% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Bus Ticke... |
| CVE-2025-31069 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Object Injecti... |
| CVE-2025-31064 | HIGH | 8.1 | 0.5% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-31060 | HIGH | 8.1 | 0.5% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-31056 | CRITICAL | 9.3 | 0.4% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Techspawn WhatsCar... |
| CVE-2025-31053 | HIGH | 7.7 | 0.4% | May 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in quantumcloud KBx Pro Ult... |
| CVE-2025-31049 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from ... |
| CVE-2025-1123 | HIGH | 7.2 | 0.3% | May 23, 2025 | The Solid Mail – SMTP email and logging made by SolidWP plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2025-5106 | HIGH | 7.3 | 3.0% | May 23, 2025 | A vulnerability was found in Fujian Kelixun 1.0. It has been classified as critical. This affects an unknown part of the... |
| CVE-2025-5105 | HIGH | 7.3 | 0.4% | May 23, 2025 | A vulnerability was found in TOZED ZLT W51 up to 1.4.2 and classified as critical. Affected by this issue is some unknow... |
| CVE-2025-41407 | HIGH | 8.3 | 1.2% | May 23, 2025 | Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report. |
| CVE-2025-3895 | CRITICAL | 9.1 | 0.4% | May 23, 2025 | Token used for resetting passwords in MegaBIP software are generated using a small space of random values combined with ... |
| CVE-2025-3894 | MEDIUM | 4.8 | 0.4% | May 23, 2025 | Text editor embedded into MegaBIP software does not neutralize user input allowing Stored XSS attacks on other users. In... |
| CVE-2025-3893 | HIGH | 8.6 | 0.3% | May 23, 2025 | While editing pages managed by MegaBIP a user with high privileges is prompted to give a reasoning for performing this a... |
| CVE-2025-36527 | HIGH | 8.3 | 20.2% | May 23, 2025 | Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports. |
| CVE-2025-4379 | MEDIUM | 5.1 | 0.4% | May 23, 2025 | DobryCMS in versions 2.* and lower is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in s... |
| CVE-2025-5096 | MEDIUM | 5.4 | 0.4% | May 23, 2025 | The TablePress plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the 'data-caption', 'data... |
| CVE-2025-47149 | MEDIUM | 6.9 | 0.1% | May 23, 2025 | The optional feature 'Anti-Virus & Sandbox' of i-FILTER contains an issue with improper pattern file validation. If expl... |
| CVE-2025-48695 | MEDIUM | 6.4 | 0.2% | May 23, 2025 | An issue was discovered in CyberDAVA before 1.1.20. A privilege escalation vulnerability allows a low-privileged user to... |
| CVE-2025-4594 | MEDIUM | 5.4 | 0.2% | May 23, 2025 | The Tournamatch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trn-ladder-registrat... |
| CVE-2025-48708 | LOW | 3.3 | 0.3% | May 23, 2025 | gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for ... |
| CVE-2025-48701 | MEDIUM | 5.4 | 0.2% | May 23, 2025 | openDCIM through 23.04 allows SQL injection in people_depts.php because prepared statements are not used. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now