2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47562 | MEDIUM | 5.3 | 0.3% | May 16, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG mapsvg allows Code Injection... |
| CVE-2025-47560 | MEDIUM | 5 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in RomanCode MapSVG mapsvg allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2025-47557 | MEDIUM | 6.5 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RomanCode MapSVG m... |
| CVE-2025-47556 | MEDIUM | 5.4 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for WordPress css3_web_pricing_tables_gr... |
| CVE-2025-47534 | MEDIUM | 4.3 | 0.2% | May 16, 2025 | Missing Authorization vulnerability in ValvePress Wordpress Auto Spinner wp-auto-spinner allows Exploiting Incorrectly C... |
| CVE-2025-46464 | MEDIUM | 6.5 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scripteo Ads Pro a... |
| CVE-2025-40906 | CRITICAL | 9.8 | 0.5% | May 16, 2025 | BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities. Those... |
| CVE-2025-39537 | HIGH | 7.1 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blaze Concepts Bet... |
| CVE-2025-39511 | MEDIUM | 4.3 | 0.2% | May 16, 2025 | Missing Authorization vulnerability in ValvePress Pinterest Automatic Pin wp-pinterest-automatic allows Exploiting Incor... |
| CVE-2025-39509 | MEDIUM | 5.4 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNcode TNC Fli... |
| CVE-2025-39507 | HIGH | 8.8 | 0.7% | May 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39493 | HIGH | 8.8 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in ValvePress Rankie valvepress-rankie allows Exploiting Incorrectly Configured Acce... |
| CVE-2025-39492 | HIGH | 7.5 | 0.4% | May 16, 2025 | Path Traversal vulnerability in WHMPress WHMpress allows Relative Path Traversal. This issue affects WHMpress: from 6.2 ... |
| CVE-2025-39491 | HIGH | 8.1 | 0.4% | May 16, 2025 | Path Traversal vulnerability in WHMPress WHMpress allows Path Traversal. This issue affects WHMpress: from 6.2 through r... |
| CVE-2025-39482 | HIGH | 8.8 | 0.4% | May 16, 2025 | Missing Authorization vulnerability in imithemes Eventer eventer allows Exploiting Incorrectly Configured Access Control... |
| CVE-2025-39481 | CRITICAL | 9.8 | 0.4% | May 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in imithemes Eventer ... |
| CVE-2025-32643 | CRITICAL | 9.3 | 0.4% | May 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPGYM all... |
| CVE-2025-32310 | HIGH | 8.8 | 0.2% | May 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeMove QuickCal - Appointment Booking Calendar for WordPress quick... |
| CVE-2025-32307 | HIGH | 8.5 | 0.3% | May 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Chame... |
| CVE-2025-32306 | HIGH | 8.5 | 0.3% | May 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Radio... |
| CVE-2025-32301 | HIGH | 8.5 | 0.3% | May 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Count... |
| CVE-2025-32299 | MEDIUM | 4.3 | 0.3% | May 16, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Themovation QuickCal - Appoi... |
| CVE-2025-32296 | MEDIUM | 5.3 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Exploiting Inc... |
| CVE-2025-32295 | MEDIUM | 4.3 | 0.2% | May 16, 2025 | Missing Authorization vulnerability in wordpresschef Salon Booking Pro salon-booking-plugin-pro-cc allows Exploiting Inc... |
| CVE-2025-32290 | HIGH | 8.5 | 0.3% | May 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Stick... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now