2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-39375MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Ashok G Easy Child Theme Creator easy-child-theme-creator allows Cros...
CVE-2025-39374HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in aseem1234 Best Posts Summary best-posts-summary allows Stored XSS.Thi...
CVE-2025-39373MEDIUM5.3Missing Authorization vulnerability in jegtheme JNews jnews allows Exploiting Incorrectly Configured Access Control Secu...
CVE-2025-39371MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Sanjeev Mohindra Author Box Plugin With Different Description author-...
CVE-2025-39370HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cnilsson iCafe Lib...
CVE-2025-39369MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sihibbs Posts for ...
CVE-2025-39368MEDIUM5.3Missing Authorization vulnerability in ed4becky Rootspersona rootspersona allows Exploiting Incorrectly Configured Acces...
CVE-2025-39364HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-39353MEDIUM5.3Missing Authorization vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Exploiting Incorrectly Configu...
CVE-2025-39351MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Cross Site Request...
CVE-2025-26920MEDIUM5.4Missing Authorization vulnerability in pressmaximum Customify customify-theme allows Exploiting Incorrectly Configured A...
CVE-2025-26867MEDIUM5.3Missing Authorization vulnerability in Themes4WP Bulk allows Accessing Functionality Not Properly Constrained by ACLs.Th...
CVE-2025-4948HIGH7.5A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used b...
CVE-2025-4939MEDIUM6.1A vulnerability classified as problematic was found in PHPGurukul Credit Card Application Management System 1.0. This vu...
CVE-2025-4938CRITICAL9.8A vulnerability was found in PHPGurukul Employee Record Management System 1.3. It has been rated as critical. Affected b...
CVE-2025-4876MEDIUM4.4ConnectWise-Password-Encryption-Utility.exe in ConnectWise Risk Assessment allows an attacker to extract a hardcoded AES...
CVE-2025-32920MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in templateinvaders T...
CVE-2025-31262MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS S...
CVE-2025-31185LOW3.3A logic issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3. Photos in the Hidden ...
CVE-2025-26621MEDIUM6.8OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6....
CVE-2025-24189HIGH8.8The issue was addressed with improved checks. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoi...
CVE-2025-24184MEDIUM5.5The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, m...
CVE-2025-24183MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Vent...
CVE-2025-23988HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruno Cavalcante G...
CVE-2025-23986HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fyrewurks Tiki Tim...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now