2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20162 | HIGH | 8.6 | 0.4% | May 7, 2025 | A vulnerability in the DHCP snooping security feature of Cisco IOS XE Software could allow an unauthenticated, remote at... |
| CVE-2025-20154 | HIGH | 8.6 | 0.4% | May 7, 2025 | A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature of Cisco IOS Software and Cisco IOS XE... |
| CVE-2025-20140 | HIGH | 7.4 | 0.2% | May 7, 2025 | A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLC... |
| CVE-2025-20122 | HIGH | 7.8 | 0.1% | May 7, 2025 | A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated... |
| CVE-2025-47685 | HIGH | 7.1 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Moloni Contribuinte Checkout contribuinte-checkout allows Stored XSS.... |
| CVE-2025-47683 | HIGH | 7.2 | 0.5% | May 7, 2025 | Deserialization of Untrusted Data vulnerability in Florent Maillefaud WP Maintenance wp-maintenance allows Object Inject... |
| CVE-2025-47655 | HIGH | 7.1 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in themarketer2023 theMarketer themarketer allows Stored XSS.This issue ... |
| CVE-2025-47653 | HIGH | 7.5 | 0.5% | May 7, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47649 | HIGH | 8.8 | 0.4% | May 7, 2025 | Path Traversal: '.../...//' vulnerability in StackWC Open Close WooCommerce Store woc-open-close allows PHP Local File I... |
| CVE-2025-47648 | HIGH | 7.1 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in axima Pays – WooCommerce Payment Gateway axima-payment-gateway allows... |
| CVE-2025-47643 | HIGH | 7.6 | 0.4% | May 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX ... |
| CVE-2025-47639 | HIGH | 7.1 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Supertext Supertext Translation and Proofreading polylang-supertext a... |
| CVE-2025-47636 | HIGH | 7.5 | 0.6% | May 7, 2025 | Path Traversal: '.../...//' vulnerability in Fernando Briano List category posts list-category-posts allows PHP Local Fi... |
| CVE-2025-47633 | HIGH | 8.8 | 0.2% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Awin Awin – Advertiser Tracking for WooCommerce awin-advertiser-track... |
| CVE-2025-47629 | HIGH | 7.2 | 0.5% | May 7, 2025 | Deserialization of Untrusted Data vulnerability in Mario Peshev WP-CRM System wp-crm-system allows Object Injection.This... |
| CVE-2025-47628 | HIGH | 8.8 | 0.3% | May 7, 2025 | Missing Authorization vulnerability in quomodosoft QS Dark Mode qs-dark-mode allows Exploiting Incorrectly Configured Ac... |
| CVE-2025-47624 | HIGH | 8.8 | 0.2% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in apasionados DoFollow Case by Case dofollow-case-by-case allows Cross ... |
| CVE-2025-47620 | HIGH | 7.1 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in bundgaard Martins Free Monetized Ad Exchange Network martins-free-and... |
| CVE-2025-47612 | HIGH | 8.8 | 0.3% | May 7, 2025 | Missing Authorization vulnerability in ClickWhale ClickWhale clickwhale allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-47587 | HIGH | 7.6 | 0.4% | May 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMT... |
| CVE-2025-47550 | HIGH | 7.2 | 0.4% | May 7, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Instantio instantio allows Upload a Web Shell ... |
| CVE-2025-47549 | HIGH | 7.2 | 0.4% | May 7, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Themefic BEAF beaf-before-and-after-gallery allows Uplo... |
| CVE-2025-47546 | HIGH | 8.8 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Cross Site Requ... |
| CVE-2025-47545 | HIGH | 8.1 | 0.3% | May 7, 2025 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Ays Pro Pol... |
| CVE-2025-47544 | HIGH | 7.2 | 0.4% | May 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in acowebs Dynamic Pr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now