2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-47613HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla School Ma...
CVE-2025-47611HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Khaled User Meta u...
CVE-2025-47603HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Belingo belingoGeo belin...
CVE-2025-47575HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Ma...
CVE-2025-47558HIGH7.5Missing Authorization vulnerability in RomanCode MapSVG mapsvg allows Accessing Functionality Not Properly Constrained b...
CVE-2025-47541HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in WPFunnels Mail Mint mail-mint allows Retrieve Embedde...
CVE-2025-47535HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpopal Opal Woo Custom P...
CVE-2025-47512HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in tainacan Tainacan tainac...
CVE-2025-47492HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Drag and Dro...
CVE-2025-47478HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileG...
CVE-2025-47461HIGH8.8Authentication Bypass Using an Alternate Path or Channel vulnerability in mediaticus Subaccounts for WooCommerce subacco...
CVE-2025-47458HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in B2itech B2i Invest...
CVE-2025-46537HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ctltwp Section Wid...
CVE-2025-46526HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in janekniefeldt My C...
CVE-2025-46515HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar C...
CVE-2025-46488HIGH7.1Missing Authorization vulnerability in dastan800 Visual Builder visual-builder allows Reflected XSS.This issue affects V...
CVE-2025-46487HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sftranna EC Author...
CVE-2025-46474HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-46463HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yamna Khawaja Mail...
CVE-2025-46458HIGH8.2Cross-Site Request Forgery (CSRF) vulnerability in x000x occupancyplan occupancyplan allows SQL Injection.This issue aff...
CVE-2025-46456HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason Theme Blvd S...
CVE-2025-46454HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-46448HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reifsnyderb Docume...
CVE-2025-46446HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ivanrojas Libro de...
CVE-2025-46444HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now