2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39503 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in GoodLayers Goodlayers Hotel gdlr-hotel allows Object Injection.This i... |
| CVE-2025-39501 | CRITICAL | 9.3 | 0.4% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GoodLayers Goodlay... |
| CVE-2025-39500 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in GoodLayers Goodlayers Hostel gdlr-hostel allows Object Injection.This... |
| CVE-2025-39499 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in BoldThemes Medicare medicare allows Object Injection.This issue affec... |
| CVE-2025-39495 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in BoldThemes Avantage avantage allows Object Injection.This issue affec... |
| CVE-2025-39494 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39489 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | Incorrect Privilege Assignment vulnerability in pebas CouponXL couponxl allows Privilege Escalation.This issue affects C... |
| CVE-2025-39485 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour grandtour allows Object Injection.This issue af... |
| CVE-2025-39480 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in ThemeMakers Car Dealer cardealer allows Object Injection.This issue a... |
| CVE-2025-32292 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in AncoraThemes Jarvis – Night Club, Concert, Festival WordPress jarvis ... |
| CVE-2025-31927 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in themeton Acerola allows Object Injection. This issue affects Acerola:... |
| CVE-2025-31918 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro... |
| CVE-2025-31916 | CRITICAL | 9 | 0.4% | May 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in joy2012bd JP Students Result Management System Premium ... |
| CVE-2025-31914 | CRITICAL | 9.3 | 0.4% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Pixel... |
| CVE-2025-31631 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in AncoraThemes Fish House fish-house allows Object Injection.This issue... |
| CVE-2025-31430 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in themeton The Business allows Object Injection. This issue affects The... |
| CVE-2025-31423 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in AncoraThemes Umberto umberto allows Object Injection.This issue affec... |
| CVE-2025-31397 | CRITICAL | 9.3 | 0.4% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Bus Ticke... |
| CVE-2025-31069 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Object Injecti... |
| CVE-2025-31056 | CRITICAL | 9.3 | 0.4% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Techspawn WhatsCar... |
| CVE-2025-31049 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from ... |
| CVE-2025-3895 | CRITICAL | 9.1 | 0.4% | May 23, 2025 | Token used for resetting passwords in MegaBIP software are generated using a small space of random values combined with ... |
| CVE-2025-5099 | CRITICAL | 9.8 | 0.6% | May 23, 2025 | An Out of Bounds Write occurs when the native library attempts PDF rendering, which can be exploited to achieve memory c... |
| CVE-2025-5098 | CRITICAL | 9.1 | 0.3% | May 23, 2025 | PrinterShare Android application allows the capture of Gmail authentication tokens that can be reused to access a user's... |
| CVE-2025-48373 | CRITICAL | 9.1 | 0.3% | May 22, 2025 | Schule is open-source school management system software. The application relies on client-side JavaScript (index.js) to ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now