2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32287 | HIGH | 8.5 | 0.3% | May 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Respo... |
| CVE-2025-32245 | MEDIUM | 6.5 | 0.1% | May 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Chaser324 Featured Posts Scroll featured-posts-scroll allows Stored X... |
| CVE-2025-32180 | MEDIUM | 6.5 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojofywp Product C... |
| CVE-2025-31928 | HIGH | 8.5 | 0.3% | May 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Multi... |
| CVE-2025-31926 | HIGH | 8.5 | 0.3% | May 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Stick... |
| CVE-2025-31923 | MEDIUM | 5.4 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in QuanticaLabs CSS3 Accordions for WordPress css3_accordions allows Exploiting Inco... |
| CVE-2025-31922 | HIGH | 7.1 | 0.1% | May 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in QuanticaLabs CSS3 Accordions for WordPress css3_accordions allows Sto... |
| CVE-2025-31921 | MEDIUM | 4.3 | 0.1% | May 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Ultimate Tours Builder WP_UltimateToursBuilder allows Cross... |
| CVE-2025-31915 | MEDIUM | 5.4 | 0.1% | May 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder pixel... |
| CVE-2025-31641 | HIGH | 8.5 | 0.4% | May 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup UberS... |
| CVE-2025-31640 | HIGH | 8.5 | 0.4% | May 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Magic... |
| CVE-2025-31639 | MEDIUM | 4.3 | 0.2% | May 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in themeton Spare allows Cross Site Request Forgery. This issue affects ... |
| CVE-2025-31637 | HIGH | 8.5 | 0.4% | May 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup SHOUT... |
| CVE-2025-31630 | MEDIUM | 5.3 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in themeton The Business allows Exploiting Incorrectly Configured Access Control Sec... |
| CVE-2025-31071 | MEDIUM | 5.3 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Exploiting Incorrectly Con... |
| CVE-2025-31068 | MEDIUM | 4.3 | 0.2% | May 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in themeton Seven Stars allows Cross Site Request Forgery. This issue af... |
| CVE-2025-31066 | MEDIUM | 5.3 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in themeton Acerola acerola allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2025-31065 | MEDIUM | 5.3 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in themeton Rozario allows Exploiting Incorrectly Configured Access Control Security... |
| CVE-2025-31063 | MEDIUM | 4.3 | 0.2% | May 16, 2025 | Missing Authorization vulnerability in redqteam Wishlist wishlist allows Exploiting Incorrectly Configured Access Contro... |
| CVE-2025-31062 | MEDIUM | 4.3 | 0.3% | May 16, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in redqteam Wishlist wishlist a... |
| CVE-2025-4785 | CRITICAL | 9.8 | 0.6% | May 16, 2025 | A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. Affected by thi... |
| CVE-2025-4782 | HIGH | 8.8 | 0.5% | May 16, 2025 | A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This ... |
| CVE-2025-4781 | HIGH | 8.8 | 0.5% | May 16, 2025 | A vulnerability classified as critical has been found in PHPGurukul Park Ticketing Management System 2.0. Affected is an... |
| CVE-2025-4478 | MEDIUM | 6.5 | 0.4% | May 16, 2025 | A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a se... |
| CVE-2025-47916 | CRITICAL | 9.8 | 79.2% | May 16, 2025 | Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now