2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-32287HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Respo...
CVE-2025-32245MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in Chaser324 Featured Posts Scroll featured-posts-scroll allows Stored X...
CVE-2025-32180MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojofywp Product C...
CVE-2025-31928HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Multi...
CVE-2025-31926HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Stick...
CVE-2025-31923MEDIUM5.4Missing Authorization vulnerability in QuanticaLabs CSS3 Accordions for WordPress css3_accordions allows Exploiting Inco...
CVE-2025-31922HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in QuanticaLabs CSS3 Accordions for WordPress css3_accordions allows Sto...
CVE-2025-31921MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Ultimate Tours Builder WP_UltimateToursBuilder allows Cross...
CVE-2025-31915MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder pixel...
CVE-2025-31641HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup UberS...
CVE-2025-31640HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Magic...
CVE-2025-31639MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in themeton Spare allows Cross Site Request Forgery. This issue affects ...
CVE-2025-31637HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup SHOUT...
CVE-2025-31630MEDIUM5.3Missing Authorization vulnerability in themeton The Business allows Exploiting Incorrectly Configured Access Control Sec...
CVE-2025-31071MEDIUM5.3Missing Authorization vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Exploiting Incorrectly Con...
CVE-2025-31068MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in themeton Seven Stars allows Cross Site Request Forgery. This issue af...
CVE-2025-31066MEDIUM5.3Missing Authorization vulnerability in themeton Acerola acerola allows Exploiting Incorrectly Configured Access Control ...
CVE-2025-31065MEDIUM5.3Missing Authorization vulnerability in themeton Rozario allows Exploiting Incorrectly Configured Access Control Security...
CVE-2025-31063MEDIUM4.3Missing Authorization vulnerability in redqteam Wishlist wishlist allows Exploiting Incorrectly Configured Access Contro...
CVE-2025-31062MEDIUM4.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in redqteam Wishlist wishlist a...
CVE-2025-4785CRITICAL9.8A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. Affected by thi...
CVE-2025-4782HIGH8.8A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This ...
CVE-2025-4781HIGH8.8A vulnerability classified as critical has been found in PHPGurukul Park Ticketing Management System 2.0. Affected is an...
CVE-2025-4478MEDIUM6.5A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a se...
CVE-2025-47916CRITICAL9.8Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now