2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-53252HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-53245HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Afzal Multani WP L...
CVE-2025-53239HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bnovotny User Regi...
CVE-2025-52764HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in marielav flexoslid...
CVE-2025-49909HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci ...
CVE-2025-49905HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginsCafe Range ...
CVE-2025-49904HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam Boo...
CVE-2025-49900HIGH8.8Incorrect Privilege Assignment vulnerability in bPlugins Advanced scrollbar advanced-scrollbar allows Privilege Escalati...
CVE-2025-49394HIGH7.1Missing Authorization vulnerability in bPlugins Image Gallery block – Create and display photo gallery/photo album. 3d-i...
CVE-2025-49390HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in christophrado Cook...
CVE-2025-49386HIGH8.8Deserialization of Untrusted Data vulnerability in Scott Reilly Preserve Code Formatting preserve-code-formatting allows...
CVE-2025-48330HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-48290HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-48090HIGH8.1Path Traversal: '.../...//' vulnerability in CocoBasic Blanka - One Page WordPress Theme blanka-wp allows PHP Local File...
CVE-2025-48085HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in ZIPANG Simple Stripe simple-stripe allows Stored XSS.This issue affec...
CVE-2025-48083HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in andriassundskard wpNamedUsers wpnamedusers allows Stored XSS.This iss...
CVE-2025-48078HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Norbert Slick Google Map slick-google-map allows Stored XSS.This issu...
CVE-2025-48077HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in nitinmaurya12 Block Country block-country allows Stored XSS.This issu...
CVE-2025-39468HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-39467HIGH8.1Path Traversal: '.../...//' vulnerability in Mikado-Themes Wanderland wanderland allows PHP Local File Inclusion.This is...
CVE-2025-39466HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-39463HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-31029HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bingu replyMail re...
CVE-2025-28953HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in axiomthemes smart ...
CVE-2025-12556HIGH8.8An argument injection vulnerability exists in the affected product that could allow an attacker to execute arbitrary cod...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now