2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-31631CRITICAL9.8Deserialization of Untrusted Data vulnerability in AncoraThemes Fish House fish-house allows Object Injection.This issue...
CVE-2025-31430CRITICAL9.8Deserialization of Untrusted Data vulnerability in themeton The Business allows Object Injection. This issue affects The...
CVE-2025-31423CRITICAL9.8Deserialization of Untrusted Data vulnerability in AncoraThemes Umberto umberto allows Object Injection.This issue affec...
CVE-2025-31397CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Bus Ticke...
CVE-2025-31069CRITICAL9.8Deserialization of Untrusted Data vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Object Injecti...
CVE-2025-31064HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-31060HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-31056CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Techspawn WhatsCar...
CVE-2025-31053HIGH7.7Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in quantumcloud KBx Pro Ult...
CVE-2025-31049CRITICAL9.8Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from ...
CVE-2025-1123HIGH7.2The Solid Mail – SMTP email and logging made by SolidWP plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2025-5106HIGH7.3A vulnerability was found in Fujian Kelixun 1.0. It has been classified as critical. This affects an unknown part of the...
CVE-2025-5105HIGH7.3A vulnerability was found in TOZED ZLT W51 up to 1.4.2 and classified as critical. Affected by this issue is some unknow...
CVE-2025-41407HIGH8.3Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report.
CVE-2025-3895CRITICAL9.1Token used for resetting passwords in MegaBIP software are generated using a small space of random values combined with ...
CVE-2025-3894MEDIUM4.8Text editor embedded into MegaBIP software does not neutralize user input allowing Stored XSS attacks on other users. In...
CVE-2025-3893HIGH8.6While editing pages managed by MegaBIP a user with high privileges is prompted to give a reasoning for performing this a...
CVE-2025-36527HIGH8.3Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports.
CVE-2025-4379MEDIUM5.1DobryCMS in versions 2.* and lower is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in s...
CVE-2025-5096MEDIUM5.4The TablePress plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the 'data-caption', 'data...
CVE-2025-47149MEDIUM6.9The optional feature 'Anti-Virus & Sandbox' of i-FILTER contains an issue with improper pattern file validation. If expl...
CVE-2025-48695MEDIUM6.4An issue was discovered in CyberDAVA before 1.1.20. A privilege escalation vulnerability allows a low-privileged user to...
CVE-2025-4594MEDIUM5.4The Tournamatch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trn-ladder-registrat...
CVE-2025-48708LOW3.3gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for ...
CVE-2025-48701MEDIUM5.4openDCIM through 23.04 allows SQL injection in people_depts.php because prepared statements are not used.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now