2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49070 | HIGH | 7.5 | 0.4% | Jul 4, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47627 | HIGH | 7.5 | 0.4% | Jul 4, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39487 | HIGH | 7.1 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ValvePress Rankie ... |
| CVE-2025-32311 | HIGH | 7.1 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs Press... |
| CVE-2025-32297 | HIGH | 8.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simpl... |
| CVE-2025-31037 | HIGH | 7.1 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Homey h... |
| CVE-2025-28980 | HIGH | 7.7 | 0.4% | Jul 4, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in machouinard Aviation Wea... |
| CVE-2025-28978 | HIGH | 7.1 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hung Trang Si SB B... |
| CVE-2025-28968 | HIGH | 7.1 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vladimir Prelovac ... |
| CVE-2025-24780 | HIGH | 8.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcar... |
| CVE-2025-24771 | HIGH | 7.1 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Content ... |
| CVE-2025-7060 | HIGH | 8.1 | 0.4% | Jul 4, 2025 | A vulnerability was found in Monitorr up to 1.7.6m. It has been classified as problematic. This affects an unknown part ... |
| CVE-2025-38176 | HIGH | 7.8 | 0.1% | Jul 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: binder: fix use-after-free in binderfs_evict_inode(... |
| CVE-2025-38175 | HIGH | 7.8 | 0.1% | Jul 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: binder: fix yet another UAF in binder_devices Comm... |
| CVE-2025-5920 | HIGH | 7.5 | 0.4% | Jul 4, 2025 | The Sharable Password Protected Posts before version 1.1.1 allows access to password protected posts by providing a secr... |
| CVE-2025-30979 | HIGH | 8.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Pixelatin... |
| CVE-2025-30969 | HIGH | 8.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus iFrame Im... |
| CVE-2025-30947 | HIGH | 8.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Cool fade... |
| CVE-2025-28969 | HIGH | 8.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cybio Gallery Widg... |
| CVE-2025-28967 | HIGH | 8.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Truman Conta... |
| CVE-2025-24735 | HIGH | 7.7 | 0.4% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chatra Chatra Live... |
| CVE-2025-53600 | HIGH | 7.5 | 0.2% | Jul 4, 2025 | Whale browser before 4.32.315.22 allow an attacker to bypass the Same-Origin Policy in a dual-tab environment. |
| CVE-2025-32918 | HIGH | 8.8 | 0.3% | Jul 4, 2025 | Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions... |
| CVE-2025-5372 | HIGH | 8.8 | 0.4% | Jul 4, 2025 | A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function r... |
| CVE-2025-6814 | HIGH | 7.5 | 0.4% | Jul 4, 2025 | The Booking X plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now