2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64291 | MEDIUM | 5.9 | 0.2% | Oct 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premmerce Premmerc... |
| CVE-2025-64290 | MEDIUM | 4.3 | 0.1% | Oct 29, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce Product Search for WooCommerce premmerce-search a... |
| CVE-2025-64289 | MEDIUM | 5.9 | 0.2% | Oct 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premmerce Premmerc... |
| CVE-2025-64288 | MEDIUM | 4.3 | 0.1% | Oct 29, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce premmerce allows Cross Site Request Forgery.This ... |
| CVE-2025-64286 | MEDIUM | 4.3 | 0.1% | Oct 29, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WpEstate WP Rentals wprentals allows Cross Site Request Forgery.This ... |
| CVE-2025-64285 | MEDIUM | 5.4 | 0.2% | Oct 29, 2025 | Missing Authorization vulnerability in Premmerce Premmerce Wholesale Pricing for WooCommerce premmerce-woocommerce-whole... |
| CVE-2025-64284 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-64283 | MEDIUM | 6.5 | 0.2% | Oct 29, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Rometheme RTMKit rometheme-for-elementor allows Exploi... |
| CVE-2025-64234 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | Missing Authorization vulnerability in Evergreen Content Poster Evergreen Content Poster evergreen-content-poster allows... |
| CVE-2025-64229 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting In... |
| CVE-2025-64228 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in FantasticPlugins SUMO Affili... |
| CVE-2025-64226 | MEDIUM | 4.3 | 0.1% | Oct 29, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in colabrio Stockie Extra stockie-extra allows Cross Site Request Forger... |
| CVE-2025-64220 | MEDIUM | 6.5 | 0.2% | Oct 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ReyCommerce Rey Co... |
| CVE-2025-64219 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | Missing Authorization vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Exploiting In... |
| CVE-2025-64216 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-64212 | MEDIUM | 5.4 | 0.2% | Oct 29, 2025 | Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro... |
| CVE-2025-64211 | MEDIUM | 5.3 | 0.2% | Oct 29, 2025 | Missing Authorization vulnerability in StylemixThemes Masterstudy Elementor Widgets masterstudy-elementor-widgets allows... |
| CVE-2025-64210 | MEDIUM | 5.4 | 0.2% | Oct 29, 2025 | Missing Authorization vulnerability in StylemixThemes Masterstudy Elementor Widgets masterstudy-elementor-widgets allows... |
| CVE-2025-64208 | MEDIUM | 6.5 | 0.2% | Oct 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TieLabs Jannah - E... |
| CVE-2025-64204 | MEDIUM | 6.5 | 0.2% | Oct 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeSphere SmartM... |
| CVE-2025-64202 | MEDIUM | 6.5 | 0.2% | Oct 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TieLabs Sahifa sah... |
| CVE-2025-64201 | MEDIUM | 4.3 | 0.1% | Oct 29, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in blubrry PowerPress Podcasting powerpress allows Cross Site Request Fo... |
| CVE-2025-64200 | MEDIUM | 5.9 | 0.2% | Oct 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Email T... |
| CVE-2025-64199 | MEDIUM | 5.3 | 0.2% | Oct 29, 2025 | Missing Authorization vulnerability in WpEstate wpresidence wpresidence allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-64197 | MEDIUM | 6.5 | 0.2% | Oct 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sizam Rehub rehub-... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now