2025 CVE Vulnerabilities

45,296 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-32205LOW2.7Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in piotnetdotcom Piotnet Fo...
CVE-2025-32202CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Brian Batt - elearningfreak.com Insert or Embed Articul...
CVE-2025-32199MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyale-vc Contact F...
CVE-2025-32198MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themefusecom Brizy...
CVE-2025-32160HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32158HIGH8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32145HIGH8.8Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This...
CVE-2025-32140CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail wp-remote-thumbnai...
CVE-2025-32139MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FooPlugins FooBox ...
CVE-2025-32128HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in aaronfrey Nearby L...
CVE-2025-32119HIGH8.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CardGate CardGate ...
CVE-2025-32116HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Studi7 QR Master q...
CVE-2025-32115HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Popping ...
CVE-2025-32114HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 5sterrenspecialist...
CVE-2025-31524HIGH8.8Incorrect Privilege Assignment vulnerability in John James Jacoby WP User Profiles wp-users-profiles allows Privilege Es...
CVE-2025-30582HIGH8.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in aytechnet DyaPress ERP/C...
CVE-2025-2873Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Further investigation showed...
CVE-2025-3417HIGH8.8The Embedder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalati...
CVE-2025-2809HIGH7.3The azurecurve Shortcodes in Comments plugin for WordPress is vulnerable to arbitrary shortcode execution in all version...
CVE-2025-2805HIGH7.3The ORDER POST plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including,...
CVE-2025-2719MEDIUM6.5The Swatchly – WooCommerce Variation Swatches for Products (product attributes: Image swatch, Color swatches, Label swat...
CVE-2025-0539HIGH8.8In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests th...
CVE-2025-3102HIGH8.1The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading ...
CVE-2025-3489MEDIUM6.1A vulnerability was found in Nababur Simple-User-Management-System 1.0. It has been rated as problematic. Affected by th...
CVE-2025-27690CRITICAL9.8Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthent...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now