2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48144 | MEDIUM | 6.1 | 0.1% | May 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in sidngr Import Export For WooCommerce import-export-for-woocommerce al... |
| CVE-2025-48138 | HIGH | 8.8 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in Bertha AI – Andrew Palmer BERTHA AI bertha-ai-free allows Exploiting Incorrectly ... |
| CVE-2025-48137 | MEDIUM | 6.5 | 0.3% | May 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in proxymis Interview... |
| CVE-2025-48136 | HIGH | 8.8 | 0.4% | May 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-48135 | MEDIUM | 5.4 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aptivadadev Aptiva... |
| CVE-2025-48134 | HIGH | 7.2 | 0.4% | May 16, 2025 | Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC WP Tabs wp-expand-tabs-free allows Object Injection.... |
| CVE-2025-48132 | MEDIUM | 5.4 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pencilwp X Addons ... |
| CVE-2025-48131 | MEDIUM | 6.5 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saiful Islam Ultra... |
| CVE-2025-48128 | MEDIUM | 4.3 | 0.2% | May 16, 2025 | Missing Authorization vulnerability in Sharespine Sharespine Woocommerce Connector sharespine-woocommerce-connector allo... |
| CVE-2025-48127 | MEDIUM | 6.5 | 0.2% | May 16, 2025 | Missing Authorization vulnerability in App Cheap Push notification for Mobile and Web app push-notification-mobile-and-w... |
| CVE-2025-48121 | MEDIUM | 6.5 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Steve Puddick WP N... |
| CVE-2025-48120 | MEDIUM | 5.3 | 0.2% | May 16, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vect... |
| CVE-2025-48119 | MEDIUM | 5.3 | 0.2% | May 16, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in RS WP THEMES RS WP Book Showcase rs-wp-books-... |
| CVE-2025-48117 | MEDIUM | 5.3 | 0.2% | May 16, 2025 | Missing Authorization vulnerability in kilbot WooCommerce POS woocommerce-pos allows Exploiting Incorrectly Configured A... |
| CVE-2025-48116 | MEDIUM | 5.3 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in Ashan Perera EventON eventon-lite allows Accessing Functionality Not Properly Con... |
| CVE-2025-48115 | MEDIUM | 4.3 | 0.1% | May 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Javier Revilla ValidateCertify validar-certificados-de-cursos allows ... |
| CVE-2025-48114 | HIGH | 7.1 | 0.1% | May 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Shayan Farhang Pazhooh ShayanWeb Admin FontChanger shayanweb-admin-fo... |
| CVE-2025-48113 | MEDIUM | 6.5 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Broadstreet Broads... |
| CVE-2025-48112 | HIGH | 7.1 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in karimmughal Dot ht... |
| CVE-2025-48080 | MEDIUM | 6.5 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncann... |
| CVE-2025-48079 | MEDIUM | 4.3 | 0.2% | May 16, 2025 | Missing Authorization vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Ex... |
| CVE-2025-47693 | HIGH | 7.5 | 0.5% | May 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47567 | HIGH | 7.6 | 0.4% | May 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Video... |
| CVE-2025-47564 | MEDIUM | 5.3 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in ashanjay EventON eventon allows Accessing Functionality Not Properly Constrained ... |
| CVE-2025-47563 | MEDIUM | 5.3 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in villatheme CURCY woocommerce-multi-currency allows Accessing Functionality Not Pr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now