2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49935 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49930 | HIGH | 7.1 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSear... |
| CVE-2025-49926 | HIGH | 7.2 | 0.2% | Oct 22, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Laborator Kalium kalium allows Code Injection... |
| CVE-2025-49925 | HIGH | 7.5 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constra... |
| CVE-2025-49924 | HIGH | 7.2 | 0.4% | Oct 22, 2025 | Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privil... |
| CVE-2025-49921 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49916 | HIGH | 8.6 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Accessing Functional... |
| CVE-2025-49911 | HIGH | 7.1 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpinstinct WooComm... |
| CVE-2025-49910 | HIGH | 8.2 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Accessing Functionality No... |
| CVE-2025-49378 | HIGH | 8.5 | 0.4% | Oct 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Boo... |
| CVE-2025-48338 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-48098 | HIGH | 7.1 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Mak... |
| CVE-2025-48097 | HIGH | 7.1 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shiva WSAnalytics ... |
| CVE-2025-48093 | HIGH | 7.1 | 0.3% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Calvaweb Password ... |
| CVE-2025-48092 | HIGH | 7.1 | 0.3% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jurajpuchky Fix Mu... |
| CVE-2025-48091 | HIGH | 8.5 | 0.4% | Oct 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alexander AnyComme... |
| CVE-2025-48082 | HIGH | 8.8 | 0.4% | Oct 22, 2025 | Incorrect Privilege Assignment vulnerability in Progress Planner Progress Planner progress-planner allows Privilege Esca... |
| CVE-2025-39534 | HIGH | 7.1 | 0.3% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Somonator Terms Di... |
| CVE-2025-32657 | HIGH | 7.5 | 0.6% | Oct 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32283 | HIGH | 8.8 | 0.6% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in designthemes Solar Energy solar allows Object Injection.This issue af... |
| CVE-2025-31634 | HIGH | 8.8 | 0.6% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in designthemes Insurance insurance allows Object Injection.This issue a... |
| CVE-2025-30944 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Missing Authorization vulnerability in Essekia Tablesome Table Premium tablesome-premium allows Accessing Functionality ... |
| CVE-2025-11965 | HIGH | 7.5 | 0.5% | Oct 22, 2025 | In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], a StaticHandler configuration for restricting access to h... |
| CVE-2025-61035 | HIGH | 7.7 | 0.1% | Oct 22, 2025 | The seffaflik thru 0.0.9 is vulnerable to symlink attacks due to incorrect default permissions given to the .kimlik file... |
| CVE-2025-11086 | HIGH | 8.1 | 0.4% | Oct 22, 2025 | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege e... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now