2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39389 | CRITICAL | 9.3 | 0.3% | May 19, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solid Plugins Anal... |
| CVE-2025-39386 | CRITICAL | 9.3 | 0.3% | May 19, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla Hospital ... |
| CVE-2025-39380 | CRITICAL | 10 | 0.4% | May 19, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System hospital-management... |
| CVE-2025-39372 | HIGH | 7.1 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elbisnero WordPres... |
| CVE-2025-39366 | HIGH | 8.8 | 0.3% | May 19, 2025 | Incorrect Privilege Assignment vulnerability in Rocket Apps wProject.This issue affects wProject: from n/a before 5.8.0. |
| CVE-2025-39365 | HIGH | 7.1 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rocket Apps wProje... |
| CVE-2025-39357 | HIGH | 8.5 | 0.3% | May 19, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla Hospital ... |
| CVE-2025-39356 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | Deserialization of Untrusted Data vulnerability in Chimpstudio Foodbakery Sticky Cart foodbakery-sticky-cart allows Obje... |
| CVE-2025-39355 | HIGH | 8.5 | 0.3% | May 19, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp FAT Servic... |
| CVE-2025-39354 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Conference grandconference allows Object Injection.T... |
| CVE-2025-39352 | HIGH | 8.2 | 0.3% | May 19, 2025 | Missing Authorization vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Exploiting Incorrectly Configu... |
| CVE-2025-39350 | HIGH | 8.2 | 0.3% | May 19, 2025 | Missing Authorization vulnerability in Rocket Apps wProject.This issue affects wProject: from n/a before 5.8.0. |
| CVE-2025-39349 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | Deserialization of Untrusted Data vulnerability in Potenzaglobalsolutions CiyaShop ciyashop allows Object Injection.This... |
| CVE-2025-39348 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.T... |
| CVE-2025-32928 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | Deserialization of Untrusted Data vulnerability in ThemeGoods Altair altair allows Object Injection.This issue affects A... |
| CVE-2025-32927 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | Deserialization of Untrusted Data vulnerability in Chimpstudio FoodBakery wp-foodbakery allows Object Injection.This iss... |
| CVE-2025-32926 | CRITICAL | 9.8 | 0.5% | May 19, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeGoods Grand Restaur... |
| CVE-2025-32925 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32924 | HIGH | 8.5 | 0.3% | May 19, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp Revy revy ... |
| CVE-2025-31027 | MEDIUM | 6.1 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jocoxdesign Tiger ... |
| CVE-2025-47934 | HIGH | 8.7 | 0.6% | May 19, 2025 | OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. Startinf in version 5.0.1 and prior to versions 5.11.... |
| CVE-2025-47581 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | Deserialization of Untrusted Data vulnerability in elbisnero WordPress Events Calendar Registration & Tickets wpeventplu... |
| CVE-2025-47577 | CRITICAL | 10 | 4.9% | May 19, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce... |
| CVE-2025-47284 | CRITICAL | 9.9 | 0.4% | May 19, 2025 | Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability... |
| CVE-2025-47283 | CRITICAL | 9.9 | 0.5% | May 19, 2025 | Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now