2025 CVE Vulnerabilities
45,296 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39442 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in MessageMetric Review Wave – Google Places Reviews review-wave-google-... |
| CVE-2025-39441 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in swedish boy Dashboard Notepads dashboard-notepads allows Stored XSS.T... |
| CVE-2025-39440 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Rajesh Broken Links Remover broken-links-remover allows Stored XSS.Th... |
| CVE-2025-39439 | MEDIUM | 5.3 | 0.3% | Apr 17, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Markus Drubba wpLike2Get wpl... |
| CVE-2025-39438 | MEDIUM | 4.3 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in momen2009 Theme Changer theme-changer allows Cross Site Request Forge... |
| CVE-2025-39437 | MEDIUM | 4.3 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Boone Gorges Anthologize anthologize allows Cross Site Request Forger... |
| CVE-2025-39436 | CRITICAL | 9.1 | 0.6% | Apr 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw idraw allows Using Malicious Files.This i... |
| CVE-2025-39435 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in davidfcarr My Marginalia my-marginalia allows Stored XSS.This issue a... |
| CVE-2025-39434 | MEDIUM | 4.3 | 0.3% | Apr 17, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Scott Taylor Avatar avatar allows Exploiting Incorrect... |
| CVE-2025-39433 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in beke_ro Bknewsticker bknewsticker allows Stored XSS.This issue affect... |
| CVE-2025-39432 | HIGH | 7.1 | 0.2% | Apr 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in antonchanning bbPr... |
| CVE-2025-39431 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Aaron Forgue Amazon Showcase WordPress Plugin amazon-showcase-wordpre... |
| CVE-2025-39430 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Alexander Rauscha mLanguage mlanguage allows Stored XSS.This issue af... |
| CVE-2025-39429 | HIGH | 7.5 | 0.6% | Apr 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39428 | MEDIUM | 5.9 | 0.2% | Apr 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maros Pristas Grav... |
| CVE-2025-39427 | MEDIUM | 5.9 | 0.2% | Apr 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beth Tucker Long W... |
| CVE-2025-39426 | MEDIUM | 4.3 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in illow illow – Cookies Consent lgpd-compliant-cookie-banner allows Cro... |
| CVE-2025-39425 | MEDIUM | 4.3 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in pixelgrade Style Manager style-manager allows Cross Site Request Forg... |
| CVE-2025-39424 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in simplemaps Simple Maps interactive-maps allows Stored XSS.This issue ... |
| CVE-2025-39423 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Jenst Add to Header add-to-header allows Stored XSS.This issue affect... |
| CVE-2025-39422 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in PResponsive WP Social Bookmarking wp-social-bookmarking allows Stored... |
| CVE-2025-39421 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Mustafa KUCUK WP Sticky Side Buttons wp-sticky-side-buttons allows St... |
| CVE-2025-39420 | HIGH | 7.1 | 0.2% | Apr 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ruudkok WP Twitter... |
| CVE-2025-39419 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in David Miller Revision Diet revision-diet allows Stored XSS.This issue... |
| CVE-2025-39418 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ajayver RSS Manager rss-manager allows Stored XSS.This issue affects ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now