2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59588 | HIGH | 7.5 | 0.4% | Sep 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-59572 | HIGH | 8.8 | 0.2% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Cross Site Request Fo... |
| CVE-2025-59570 | HIGH | 7.6 | 0.3% | Sep 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFunnels Mail Min... |
| CVE-2025-59430 | HIGH | 8.2 | 0.4% | Sep 22, 2025 | Mesh Connect JS SDK contains JS libraries for integrating with Mesh Connect. Prior to version 3.3.2, the lack of sanitiz... |
| CVE-2025-58973 | HIGH | 7.5 | 0.5% | Sep 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-58956 | HIGH | 7.1 | 0.1% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Attractive Donations System wp-attractive-donations-system-... |
| CVE-2025-58690 | HIGH | 7.1 | 0.1% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ptibogxiv Doliconnect doliconnect allows Stored XSS.This issue affect... |
| CVE-2025-58688 | HIGH | 7.1 | 0.1% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Casengo Casengo Live Chat Support the-casengo-chat-widget allows Stor... |
| CVE-2025-58687 | HIGH | 7.1 | 0.1% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WP CMS Ninja Current Age Plugin current-age allows Stored XSS.This is... |
| CVE-2025-58686 | HIGH | 8.5 | 0.2% | Sep 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quadlayers Perfect... |
| CVE-2025-58677 | HIGH | 7.1 | 0.1% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in puravida1976 ShrinkTheWeb (STW) Website Previews shrinktheweb-website... |
| CVE-2025-58676 | HIGH | 7.1 | 0.1% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in extendyourweb HORIZONTAL SLIDER horizontal-slider allows Stored XSS.T... |
| CVE-2025-58671 | HIGH | 7.1 | 0.2% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in morganrichards Auc... |
| CVE-2025-58670 | HIGH | 7.1 | 0.1% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Shankaranand Maurya WP Content Protection wp-content-protection allow... |
| CVE-2025-58662 | HIGH | 7.2 | 0.4% | Sep 22, 2025 | Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support awesome-support allows Object Injectio... |
| CVE-2025-58657 | HIGH | 7.1 | 0.1% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in EdwardBock Grid grid allows Stored XSS.This issue affects Grid: from ... |
| CVE-2025-58270 | HIGH | 7.1 | 0.1% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in NIX Solutions Ltd NIX Anti-Spam Light nix-anti-spam-light allows Cros... |
| CVE-2025-58268 | HIGH | 7.1 | 0.1% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WPMK WPMK PDF Generator wpmk-pdf-generator allows Stored XSS.This iss... |
| CVE-2025-58267 | HIGH | 7.1 | 0.1% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Aftabul Islam Stock Message stock-message allows Stored XSS.This issu... |
| CVE-2025-58262 | HIGH | 7.1 | 0.1% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WPDirectoryKit Sweet Energy Efficiency sweet-energy-efficiency allows... |
| CVE-2025-58261 | HIGH | 7.1 | 0.1% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in PressPage Entertainment Inc Mavis HTTPS to HTTP Redirection mavis-htt... |
| CVE-2025-58259 | HIGH | 7.1 | 0.1% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in scriptsbundle Nokri nokri allows Cross Site Request Forgery.This issu... |
| CVE-2025-58250 | HIGH | 8.8 | 0.2% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ApusTheme Findgo fingo allows Authentication Bypass.This issue affect... |
| CVE-2025-58244 | HIGH | 8.8 | 0.2% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Anps Constructo constructo allows Object Injection.This issue affects... |
| CVE-2025-58015 | HIGH | 7.5 | 0.3% | Sep 22, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Ays Pro Quiz Maker quiz-make... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now