2025 CVE Vulnerabilities
45,280 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47602 | MEDIUM | 5.4 | 0.3% | May 7, 2025 | Missing Authorization vulnerability in ammarahmad786 Calculate Prices based on Distance For WooCommerce calculate-prices... |
| CVE-2025-47597 | MEDIUM | 4.3 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Maulik Vora WP Podcasts Manager wp-podcasts-manager allows Cross Site... |
| CVE-2025-47596 | MEDIUM | 4.3 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Beacon Lead Magnets and Lead Capture beacon-by allows Cro... |
| CVE-2025-47595 | MEDIUM | 5.9 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darshan Saroya Col... |
| CVE-2025-47594 | MEDIUM | 4.3 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in DAEXT Soccer Live Scores allows Cross Site Request Forgery. This issu... |
| CVE-2025-47593 | MEDIUM | 5.9 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jonas Hjalmarsson ... |
| CVE-2025-47592 | MEDIUM | 5.9 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Árpád Lehel Mátyus... |
| CVE-2025-47591 | MEDIUM | 4.3 | 0.3% | May 7, 2025 | Missing Authorization vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allows Exploiting Incorrectly C... |
| CVE-2025-47590 | MEDIUM | 4.3 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in JExtensions Store WPSpeed wpspeed allows Cross Site Request Forgery.T... |
| CVE-2025-47589 | MEDIUM | 6.5 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in motov.net Ebook St... |
| CVE-2025-47587 | HIGH | 7.6 | 0.4% | May 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMT... |
| CVE-2025-47551 | MEDIUM | 4.3 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ctltwp Wiki Embed wiki-embed allows Cross Site Request Forgery.This i... |
| CVE-2025-47550 | HIGH | 7.2 | 0.4% | May 7, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Instantio instantio allows Upload a Web Shell ... |
| CVE-2025-47549 | HIGH | 7.2 | 0.4% | May 7, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Themefic BEAF beaf-before-and-after-gallery allows Uplo... |
| CVE-2025-47548 | CRITICAL | 9.8 | 0.2% | May 7, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Varun Dubey Wbcom Designs - Activity Link Preview For BuddyPress act... |
| CVE-2025-47547 | MEDIUM | 5.4 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SendPulse SendPuls... |
| CVE-2025-47546 | HIGH | 8.8 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Cross Site Requ... |
| CVE-2025-47545 | HIGH | 8.1 | 0.3% | May 7, 2025 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Ays Pro Pol... |
| CVE-2025-47544 | HIGH | 7.2 | 0.4% | May 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in acowebs Dynamic Pr... |
| CVE-2025-47543 | MEDIUM | 4.3 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Cross... |
| CVE-2025-47542 | MEDIUM | 4.3 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor simple-calendar-for-elementor a... |
| CVE-2025-47540 | HIGH | 7.5 | 0.3% | May 7, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs weMail wemail allows ... |
| CVE-2025-47538 | HIGH | 7.2 | 0.4% | May 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdever Cart track... |
| CVE-2025-47537 | HIGH | 7.6 | 0.4% | May 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in add-ons.org PDF In... |
| CVE-2025-47533 | HIGH | 8.1 | 0.3% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design Graphina graphina-elementor-charts-and-graphs allows PH... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now