2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39461 | HIGH | 7.5 | 0.6% | Apr 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39455 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in IP2Location IP2Location Variables ip2location-variables allows Reflec... |
| CVE-2025-39452 | HIGH | 7.5 | 0.6% | Apr 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39442 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in MessageMetric Review Wave – Google Places Reviews review-wave-google-... |
| CVE-2025-39441 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in swedish boy Dashboard Notepads dashboard-notepads allows Stored XSS.T... |
| CVE-2025-39440 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Rajesh Broken Links Remover broken-links-remover allows Stored XSS.Th... |
| CVE-2025-39435 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in davidfcarr My Marginalia my-marginalia allows Stored XSS.This issue a... |
| CVE-2025-39433 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in beke_ro Bknewsticker bknewsticker allows Stored XSS.This issue affect... |
| CVE-2025-39432 | HIGH | 7.1 | 0.2% | Apr 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in antonchanning bbPr... |
| CVE-2025-39431 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Aaron Forgue Amazon Showcase WordPress Plugin amazon-showcase-wordpre... |
| CVE-2025-39430 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Alexander Rauscha mLanguage mlanguage allows Stored XSS.This issue af... |
| CVE-2025-39429 | HIGH | 7.5 | 0.6% | Apr 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39424 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in simplemaps Simple Maps interactive-maps allows Stored XSS.This issue ... |
| CVE-2025-39423 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Jenst Add to Header add-to-header allows Stored XSS.This issue affect... |
| CVE-2025-39422 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in PResponsive WP Social Bookmarking wp-social-bookmarking allows Stored... |
| CVE-2025-39421 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Mustafa KUCUK WP Sticky Side Buttons wp-sticky-side-buttons allows St... |
| CVE-2025-39420 | HIGH | 7.1 | 0.2% | Apr 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ruudkok WP Twitter... |
| CVE-2025-39419 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in David Miller Revision Diet revision-diet allows Stored XSS.This issue... |
| CVE-2025-39418 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ajayver RSS Manager rss-manager allows Stored XSS.This issue affects ... |
| CVE-2025-39417 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Eslam Mahmoud Redirect wordpress to welcome or landing page redirect-... |
| CVE-2025-39416 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Ichi translit it! translit-it allows Stored XSS.This issue affects tr... |
| CVE-2025-39415 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Jayesh Parejiya Social Media Links social-media-links allows Stored X... |
| CVE-2025-39414 | HIGH | 7.1 | 0.1% | Apr 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Mike spam-stopper spam-stopper allows Stored XSS.This issue affects s... |
| CVE-2025-32686 | HIGH | 8.8 | 0.5% | Apr 17, 2025 | Deserialization of Untrusted Data vulnerability in WPSpeedo Team Members wps-team allows Object Injection.This issue aff... |
| CVE-2025-32674 | HIGH | 7.1 | 0.2% | Apr 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Product ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now