2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5108 | CRITICAL | 9.8 | 0.3% | May 23, 2025 | A vulnerability was found in zongzhige ShopXO 6.5.0. It has been rated as critical. This issue affects the function Uplo... |
| CVE-2025-5107 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | A vulnerability was found in Fujian Kelixun 1.0. It has been declared as critical. This vulnerability affects unknown co... |
| CVE-2025-48289 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in AncoraThemes Kids Planet kidsplanet allows Object Injection.This issu... |
| CVE-2025-48287 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in Pagaleve Pix 4x sem juros - Pagaleve wc-pagaleve allows Object Inject... |
| CVE-2025-48283 | CRITICAL | 9.3 | 0.3% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Majestic Support M... |
| CVE-2025-47687 | CRITICAL | 10 | 0.4% | May 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeepe... |
| CVE-2025-47663 | CRITICAL | 9.9 | 0.3% | May 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System allows Upload a Web... |
| CVE-2025-47646 | CRITICAL | 9.8 | 21.7% | May 23, 2025 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas Ngunte Possi PSW Front-end Login & Regi... |
| CVE-2025-47642 | CRITICAL | 10 | 0.4% | May 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed ajar-productions-in5-em... |
| CVE-2025-47641 | CRITICAL | 10 | 0.4% | May 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in printcart Printcart Web to Print Product Designer for W... |
| CVE-2025-47640 | CRITICAL | 9.3 | 0.3% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcar... |
| CVE-2025-47637 | CRITICAL | 10 | 0.4% | May 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in STAGGS STAGGS staggs allows Upload a Web Shell to a Web... |
| CVE-2025-47599 | CRITICAL | 9.3 | 0.3% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in facturante Factura... |
| CVE-2025-47568 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in ZoomIt ZoomSounds dzs-zoomsounds allows Object Injection.This issue a... |
| CVE-2025-47539 | CRITICAL | 9.8 | 30.9% | May 23, 2025 | Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This iss... |
| CVE-2025-47532 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in CoinPayments CoinPayments.net Payment Gateway for WooCommerce coinpay... |
| CVE-2025-47530 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in WPFunnels WPFunnels wpfunnels allows Object Injection.This issue affe... |
| CVE-2025-47453 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47438 | CRITICAL | 9.8 | 0.6% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-46539 | CRITICAL | 9.3 | 0.4% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFable Fable Extr... |
| CVE-2025-46490 | CRITICAL | 9.9 | 0.4% | May 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in wordwebsoftware Crossword Compiler Puzzles crossword-co... |
| CVE-2025-46468 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-46460 | CRITICAL | 9.3 | 0.4% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Detheme Easy Guide... |
| CVE-2025-46455 | CRITICAL | 9.3 | 0.4% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in IndigoThemes WP HR... |
| CVE-2025-39504 | CRITICAL | 9.3 | 0.4% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GoodLayers Goodlay... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now