2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-64360HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-64359HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-64358MEDIUM4.3Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce wt-smart-coupons-for-woocommerce allows E...
CVE-2025-64357MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner advanced-database-cleaner allow...
CVE-2025-64356MEDIUM4.3Missing Authorization vulnerability in f1logic Insert PHP Code Snippet insert-php-code-snippet allows Exploiting Incorre...
CVE-2025-64354MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matias Ventura Gut...
CVE-2025-64353HIGH8.8Deserialization of Untrusted Data vulnerability in Chouby Polylang polylang allows Object Injection.This issue affects P...
CVE-2025-64352LOW2.7Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite al...
CVE-2025-64351MEDIUM4.3Insertion of Sensitive Information Into Sent Data vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows R...
CVE-2025-64350LOW3.8Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Exploiting Incorrectly Config...
CVE-2025-58149HIGH7.5When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the...
CVE-2025-58148HIGH7.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-58147HIGH7.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-40603MEDIUM4.5A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, aut...
CVE-2025-11602MEDIUM6.3Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obta...
CVE-2025-40106In the Linux kernel, the following vulnerability has been resolved: comedi: fix divide-by-zero in comedi_buf_munge() T...
CVE-2025-12115HIGH7.5The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versi...
CVE-2025-12041MEDIUM5.3The ERI File Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check...
CVE-2025-11843HIGH8.8Therefore Corporation GmbH has recently become aware that Therefore™ Online and Therefore™ On-Premises contain an accoun...
CVE-2025-8383MEDIUM4.3The Depicter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 4.0.4....
CVE-2025-62232HIGH7.5Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and f...
CVE-2025-30191MEDIUM5.4Malicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended act...
CVE-2025-30189HIGH7.4When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached ...
CVE-2025-30188HIGH7.5Malicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict inform...
CVE-2025-12175MEDIUM4.3The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now