2025 CVE Vulnerabilities
45,296 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32205 | LOW | 2.7 | 0.3% | Apr 10, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in piotnetdotcom Piotnet Fo... |
| CVE-2025-32202 | CRITICAL | 9.1 | 0.4% | Apr 10, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Brian Batt - elearningfreak.com Insert or Embed Articul... |
| CVE-2025-32199 | MEDIUM | 6.5 | 0.2% | Apr 10, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyale-vc Contact F... |
| CVE-2025-32198 | MEDIUM | 5.4 | 0.2% | Apr 10, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themefusecom Brizy... |
| CVE-2025-32160 | HIGH | 7.5 | 0.6% | Apr 10, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32158 | HIGH | 8.8 | 0.6% | Apr 10, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32145 | HIGH | 8.8 | 0.4% | Apr 10, 2025 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This... |
| CVE-2025-32140 | CRITICAL | 9.9 | 0.4% | Apr 10, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail wp-remote-thumbnai... |
| CVE-2025-32139 | MEDIUM | 5.9 | 0.2% | Apr 10, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FooPlugins FooBox ... |
| CVE-2025-32128 | HIGH | 7.6 | 0.4% | Apr 10, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in aaronfrey Nearby L... |
| CVE-2025-32119 | HIGH | 8.2 | 0.3% | Apr 10, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CardGate CardGate ... |
| CVE-2025-32116 | HIGH | 7.1 | 0.2% | Apr 10, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Studi7 QR Master q... |
| CVE-2025-32115 | HIGH | 7.1 | 0.2% | Apr 10, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Popping ... |
| CVE-2025-32114 | HIGH | 7.1 | 0.2% | Apr 10, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 5sterrenspecialist... |
| CVE-2025-31524 | HIGH | 8.8 | 0.3% | Apr 10, 2025 | Incorrect Privilege Assignment vulnerability in John James Jacoby WP User Profiles wp-users-profiles allows Privilege Es... |
| CVE-2025-30582 | HIGH | 8.1 | 0.6% | Apr 10, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in aytechnet DyaPress ERP/C... |
| CVE-2025-2873 | — | — | — | Apr 10, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Further investigation showed... |
| CVE-2025-3417 | HIGH | 8.8 | 0.3% | Apr 10, 2025 | The Embedder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalati... |
| CVE-2025-2809 | HIGH | 7.3 | 0.4% | Apr 10, 2025 | The azurecurve Shortcodes in Comments plugin for WordPress is vulnerable to arbitrary shortcode execution in all version... |
| CVE-2025-2805 | HIGH | 7.3 | 0.4% | Apr 10, 2025 | The ORDER POST plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including,... |
| CVE-2025-2719 | MEDIUM | 6.5 | 0.2% | Apr 10, 2025 | The Swatchly – WooCommerce Variation Swatches for Products (product attributes: Image swatch, Color swatches, Label swat... |
| CVE-2025-0539 | HIGH | 8.8 | 0.3% | Apr 10, 2025 | In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests th... |
| CVE-2025-3102 | HIGH | 8.1 | 76.2% | Apr 10, 2025 | The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading ... |
| CVE-2025-3489 | MEDIUM | 6.1 | 0.4% | Apr 10, 2025 | A vulnerability was found in Nababur Simple-User-Management-System 1.0. It has been rated as problematic. Affected by th... |
| CVE-2025-27690 | CRITICAL | 9.8 | 0.4% | Apr 10, 2025 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthent... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now