2025 CVE Vulnerabilities
45,296 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39417 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Eslam Mahmoud Redirect wordpress to welcome or landing page redirect-... |
| CVE-2025-39416 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Ichi translit it! translit-it allows Stored XSS.This issue affects tr... |
| CVE-2025-39415 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Jayesh Parejiya Social Media Links social-media-links allows Stored X... |
| CVE-2025-39414 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Mike spam-stopper spam-stopper allows Stored XSS.This issue affects s... |
| CVE-2025-32686 | HIGH | 8.8 | 0.5% | Apr 17, 2025 | Deserialization of Untrusted Data vulnerability in WPSpeedo Team Members wps-team allows Object Injection.This issue aff... |
| CVE-2025-32682 | CRITICAL | 9.9 | 0.4% | Apr 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vector-maps al... |
| CVE-2025-32674 | HIGH | 7.1 | 0.2% | Apr 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Product ... |
| CVE-2025-32670 | HIGH | 7.1 | 0.2% | Apr 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark Parnell Spark... |
| CVE-2025-32666 | HIGH | 7.1 | 0.2% | Apr 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hive Support Hive ... |
| CVE-2025-32665 | CRITICAL | 9.3 | 0.3% | Apr 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebbyTemplate Offi... |
| CVE-2025-32662 | HIGH | 8.8 | 0.4% | Apr 17, 2025 | Deserialization of Untrusted Data vulnerability in Stylemix uListing ulisting allows Object Injection.This issue affects... |
| CVE-2025-32660 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in JoomSky JS Job Manager js-jobs allows Upload a Web Shel... |
| CVE-2025-32658 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | Deserialization of Untrusted Data vulnerability in wpWax HelpGent helpgent allows Object Injection.This issue affects He... |
| CVE-2025-32655 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in DevriX Restrict User Registration restrict-user-registration allows S... |
| CVE-2025-32653 | HIGH | 7.1 | 0.2% | Apr 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lee Blue Cart66 Cl... |
| CVE-2025-32652 | CRITICAL | 9.9 | 0.3% | Apr 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in solacewp Solace Extra solace-extra allows Using Malicio... |
| CVE-2025-32651 | HIGH | 7.1 | 0.3% | Apr 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in serpednet SERPed.n... |
| CVE-2025-32649 | HIGH | 7.1 | 0.2% | Apr 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gb-plugins GB Gall... |
| CVE-2025-32648 | CRITICAL | 9.8 | 0.4% | Apr 17, 2025 | Incorrect Privilege Assignment vulnerability in Projectopia Projectopia projectopia-core allows Privilege Escalation.Thi... |
| CVE-2025-32647 | HIGH | 8.8 | 0.4% | Apr 17, 2025 | Deserialization of Untrusted Data vulnerability in PickPlugins Question Answer question-answer allows Object Injection.T... |
| CVE-2025-32646 | HIGH | 7.1 | 0.2% | Apr 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Questi... |
| CVE-2025-32639 | HIGH | 7.1 | 0.2% | Apr 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wecantrack Affilia... |
| CVE-2025-32638 | HIGH | 7.1 | 0.2% | Apr 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weptile Mobile App... |
| CVE-2025-32637 | HIGH | 7.1 | 0.2% | Apr 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ketanajani WP Dona... |
| CVE-2025-32636 | CRITICAL | 9.3 | 0.3% | Apr 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in matthewrubin Local... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now