2025 CVE Vulnerabilities
45,181 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39350 | HIGH | 8.2 | 0.3% | May 19, 2025 | Missing Authorization vulnerability in Rocket Apps wProject.This issue affects wProject: from n/a before 5.8.0. |
| CVE-2025-32924 | HIGH | 8.5 | 0.3% | May 19, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp Revy revy ... |
| CVE-2025-47934 | HIGH | 8.7 | 0.6% | May 19, 2025 | OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. Startinf in version 5.0.1 and prior to versions 5.11.... |
| CVE-2025-43839 | HIGH | 7.1 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Message... |
| CVE-2025-43837 | HIGH | 7.1 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in binti76 Total Dona... |
| CVE-2025-43836 | HIGH | 7.1 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in confuzzledduck Syn... |
| CVE-2025-43832 | HIGH | 7.1 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andreyk Remote Ima... |
| CVE-2025-39459 | HIGH | 7.3 | 0.3% | May 19, 2025 | Incorrect Privilege Assignment vulnerability in contempoinc Real Estate 7 realestate-7 allows Privilege Escalation.This ... |
| CVE-2025-39458 | HIGH | 8.1 | 0.6% | May 19, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39451 | HIGH | 7.5 | 0.3% | May 19, 2025 | Missing Authorization vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Accessing Functionality Not ... |
| CVE-2025-39449 | HIGH | 7.5 | 0.3% | May 19, 2025 | Missing Authorization vulnerability in Crocoblock JetWooBuilder jet-woo-builder allows Accessing Functionality Not Prope... |
| CVE-2025-39447 | HIGH | 7.5 | 0.3% | May 19, 2025 | Missing Authorization vulnerability in Crocoblock JetElements For Elementor jet-elements allows Accessing Functionality ... |
| CVE-2025-39411 | HIGH | 7.5 | 0.5% | May 19, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39409 | HIGH | 7.1 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pressaholic WordPr... |
| CVE-2025-39407 | HIGH | 7.1 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Caseproof, LLC Mem... |
| CVE-2025-39405 | HIGH | 8.8 | 0.3% | May 19, 2025 | Incorrect Privilege Assignment vulnerability in mojoomla WPAMS apartment-management allows Privilege Escalation.This iss... |
| CVE-2025-39403 | HIGH | 8.5 | 0.3% | May 19, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPAMS apa... |
| CVE-2025-43840 | HIGH | 7.1 | 0.1% | May 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ref CheckBot checkbot allows Stored XSS.This issue affects CheckBot: ... |
| CVE-2025-43833 | HIGH | 7.6 | 0.3% | May 19, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Amir Helzer Absolu... |
| CVE-2025-39396 | HIGH | 7.5 | 0.5% | May 19, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-27010 | HIGH | 8.1 | 0.6% | May 19, 2025 | Path Traversal: '.../...//' vulnerability in bslthemes Tastyc tastyc allows PHP Local File Inclusion.This issue affects ... |
| CVE-2025-26997 | HIGH | 7.1 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in validas Wireless B... |
| CVE-2025-26735 | HIGH | 7.5 | 0.5% | May 19, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-4940 | HIGH | 7.3 | 0.4% | May 19, 2025 | A vulnerability, which was classified as critical, has been found in 1000 Projects Daily College Class Work Report Book ... |
| CVE-2025-47576 | HIGH | 8.8 | 0.4% | May 19, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now