2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39395 | CRITICAL | 9.3 | 0.3% | May 19, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPAMS apa... |
| CVE-2025-39389 | CRITICAL | 9.3 | 0.3% | May 19, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solid Plugins Anal... |
| CVE-2025-39386 | CRITICAL | 9.3 | 0.3% | May 19, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla Hospital ... |
| CVE-2025-39380 | CRITICAL | 10 | 0.4% | May 19, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System hospital-management... |
| CVE-2025-39356 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | Deserialization of Untrusted Data vulnerability in Chimpstudio Foodbakery Sticky Cart foodbakery-sticky-cart allows Obje... |
| CVE-2025-39354 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Conference grandconference allows Object Injection.T... |
| CVE-2025-39349 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | Deserialization of Untrusted Data vulnerability in Potenzaglobalsolutions CiyaShop ciyashop allows Object Injection.This... |
| CVE-2025-39348 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.T... |
| CVE-2025-32928 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | Deserialization of Untrusted Data vulnerability in ThemeGoods Altair altair allows Object Injection.This issue affects A... |
| CVE-2025-32927 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | Deserialization of Untrusted Data vulnerability in Chimpstudio FoodBakery wp-foodbakery allows Object Injection.This iss... |
| CVE-2025-32926 | CRITICAL | 9.8 | 0.5% | May 19, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeGoods Grand Restaur... |
| CVE-2025-32925 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47581 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | Deserialization of Untrusted Data vulnerability in elbisnero WordPress Events Calendar Registration & Tickets wpeventplu... |
| CVE-2025-47577 | CRITICAL | 10 | 4.9% | May 19, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce... |
| CVE-2025-47284 | CRITICAL | 9.9 | 0.4% | May 19, 2025 | Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability... |
| CVE-2025-47283 | CRITICAL | 9.9 | 0.5% | May 19, 2025 | Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability... |
| CVE-2025-39445 | CRITICAL | 9.3 | 0.3% | May 19, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super S... |
| CVE-2025-39410 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | Deserialization of Untrusted Data vulnerability in themegusta Smart Sections Theme Builder - WPBakery Page Builder Addon... |
| CVE-2025-39406 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47582 | CRITICAL | 9.8 | 0.5% | May 19, 2025 | Deserialization of Untrusted Data vulnerability in QuantumCloud WPBot Pro Wordpress Chatbot allows Object Injection.This... |
| CVE-2025-47282 | CRITICAL | 9.9 | 0.6% | May 19, 2025 | Gardener External DNS Management is an environment to manage external DNS entries for a kubernetes cluster. A security v... |
| CVE-2025-26892 | CRITICAL | 9.9 | 0.5% | May 19, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in dkszone Celestial Aura allows Using Malicious Files.Thi... |
| CVE-2025-26872 | CRITICAL | 9.9 | 0.4% | May 19, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in dkszone Eximius allows Using Malicious Files.This issue... |
| CVE-2025-4941 | CRITICAL | 9.8 | 0.5% | May 19, 2025 | A vulnerability, which was classified as critical, was found in PHPGurukul Credit Card Application Management System 1.0... |
| CVE-2025-4938 | CRITICAL | 9.8 | 0.4% | May 19, 2025 | A vulnerability was found in PHPGurukul Employee Record Management System 1.3. It has been rated as critical. Affected b... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now