2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39375 | MEDIUM | 4.3 | 0.1% | May 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Ashok G Easy Child Theme Creator easy-child-theme-creator allows Cros... |
| CVE-2025-39374 | HIGH | 7.1 | 0.1% | May 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in aseem1234 Best Posts Summary best-posts-summary allows Stored XSS.Thi... |
| CVE-2025-39373 | MEDIUM | 5.3 | 0.2% | May 19, 2025 | Missing Authorization vulnerability in jegtheme JNews jnews allows Exploiting Incorrectly Configured Access Control Secu... |
| CVE-2025-39371 | MEDIUM | 4.3 | 0.1% | May 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Sanjeev Mohindra Author Box Plugin With Different Description author-... |
| CVE-2025-39370 | HIGH | 7.6 | 0.3% | May 19, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cnilsson iCafe Lib... |
| CVE-2025-39369 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sihibbs Posts for ... |
| CVE-2025-39368 | MEDIUM | 5.3 | 0.2% | May 19, 2025 | Missing Authorization vulnerability in ed4becky Rootspersona rootspersona allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-39364 | HIGH | 7.5 | 0.5% | May 19, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39353 | MEDIUM | 5.3 | 0.2% | May 19, 2025 | Missing Authorization vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Exploiting Incorrectly Configu... |
| CVE-2025-39351 | MEDIUM | 4.3 | 0.1% | May 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Cross Site Request... |
| CVE-2025-26920 | MEDIUM | 5.4 | 0.2% | May 19, 2025 | Missing Authorization vulnerability in pressmaximum Customify customify-theme allows Exploiting Incorrectly Configured A... |
| CVE-2025-26867 | MEDIUM | 5.3 | 0.2% | May 19, 2025 | Missing Authorization vulnerability in Themes4WP Bulk allows Accessing Functionality Not Properly Constrained by ACLs.Th... |
| CVE-2025-4948 | HIGH | 7.5 | 0.6% | May 19, 2025 | A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used b... |
| CVE-2025-4939 | MEDIUM | 6.1 | 0.4% | May 19, 2025 | A vulnerability classified as problematic was found in PHPGurukul Credit Card Application Management System 1.0. This vu... |
| CVE-2025-4938 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | A vulnerability was found in PHPGurukul Employee Record Management System 1.3. It has been rated as critical. Affected b... |
| CVE-2025-4876 | MEDIUM | 4.4 | 0.1% | May 19, 2025 | ConnectWise-Password-Encryption-Utility.exe in ConnectWise Risk Assessment allows an attacker to extract a hardcoded AES... |
| CVE-2025-32920 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in templateinvaders T... |
| CVE-2025-31262 | MEDIUM | 5.5 | 0.1% | May 19, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS S... |
| CVE-2025-31185 | LOW | 3.3 | 0.2% | May 19, 2025 | A logic issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3. Photos in the Hidden ... |
| CVE-2025-26621 | MEDIUM | 6.8 | 0.4% | May 19, 2025 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.... |
| CVE-2025-24189 | HIGH | 8.8 | 0.6% | May 19, 2025 | The issue was addressed with improved checks. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoi... |
| CVE-2025-24184 | MEDIUM | 5.5 | 0.2% | May 19, 2025 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, m... |
| CVE-2025-24183 | MEDIUM | 5.5 | 0.1% | May 19, 2025 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Vent... |
| CVE-2025-23988 | HIGH | 7.1 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruno Cavalcante G... |
| CVE-2025-23986 | HIGH | 7.1 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fyrewurks Tiki Tim... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now