2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49390 | HIGH | 7.1 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in christophrado Cook... |
| CVE-2025-49386 | HIGH | 8.8 | 0.4% | Nov 6, 2025 | Deserialization of Untrusted Data vulnerability in Scott Reilly Preserve Code Formatting preserve-code-formatting allows... |
| CVE-2025-49372 | CRITICAL | 10 | 0.4% | Nov 6, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticke... |
| CVE-2025-48330 | HIGH | 7.5 | 0.4% | Nov 6, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-48290 | HIGH | 8.1 | 0.4% | Nov 6, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-48090 | HIGH | 8.1 | 0.4% | Nov 6, 2025 | Path Traversal: '.../...//' vulnerability in CocoBasic Blanka - One Page WordPress Theme blanka-wp allows PHP Local File... |
| CVE-2025-48089 | CRITICAL | 9.3 | 0.3% | Nov 6, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rainbow-Themes Edu... |
| CVE-2025-48086 | MEDIUM | 5.5 | 0.2% | Nov 6, 2025 | Deserialization of Untrusted Data vulnerability in wpdreams Ajax Search Lite ajax-search-lite allows Object Injection.Th... |
| CVE-2025-48085 | HIGH | 7.1 | 0.1% | Nov 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ZIPANG Simple Stripe simple-stripe allows Stored XSS.This issue affec... |
| CVE-2025-48083 | HIGH | 7.1 | 0.1% | Nov 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in andriassundskard wpNamedUsers wpnamedusers allows Stored XSS.This iss... |
| CVE-2025-48078 | HIGH | 7.1 | 0.1% | Nov 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Norbert Slick Google Map slick-google-map allows Stored XSS.This issu... |
| CVE-2025-48077 | HIGH | 7.1 | 0.1% | Nov 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in nitinmaurya12 Block Country block-country allows Stored XSS.This issu... |
| CVE-2025-47588 | CRITICAL | 9.1 | 0.4% | Nov 6, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in acowebs Dynamic Pricing With Discount Rules f... |
| CVE-2025-39468 | HIGH | 8.1 | 0.6% | Nov 6, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39467 | HIGH | 8.1 | 0.5% | Nov 6, 2025 | Path Traversal: '.../...//' vulnerability in Mikado-Themes Wanderland wanderland allows PHP Local File Inclusion.This is... |
| CVE-2025-39466 | HIGH | 8.1 | 0.6% | Nov 6, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39465 | MEDIUM | 4.3 | 0.2% | Nov 6, 2025 | Missing Authorization vulnerability in flippercode Advanced Google Maps wp-google-map-gold allows Exploiting Incorrectly... |
| CVE-2025-39463 | HIGH | 7.5 | 0.5% | Nov 6, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32222 | CRITICAL | 9.9 | 0.4% | Nov 6, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Widgetlogic.org Widget Logic widget-logic all... |
| CVE-2025-31029 | HIGH | 7.1 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bingu replyMail re... |
| CVE-2025-28953 | HIGH | 8.5 | 0.3% | Nov 6, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in axiomthemes smart ... |
| CVE-2025-22288 | MEDIUM | 4.1 | 0.3% | Nov 6, 2025 | Path Traversal: '.../...//' vulnerability in WPMU DEV - Your All-in-One WordPress Platform Smush Image Compression and O... |
| CVE-2025-12556 | HIGH | 8.8 | 0.4% | Nov 6, 2025 | An argument injection vulnerability exists in the affected product that could allow an attacker to execute arbitrary cod... |
| CVE-2025-37735 | HIGH | 7 | 0.1% | Nov 6, 2025 | Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being ... |
| CVE-2025-36054 | MEDIUM | 6.1 | 0.2% | Nov 6, 2025 | IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004, 25.0.0 through 25.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now