2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-64195HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-64194MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress Eduma ed...
CVE-2025-60075HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Allegro Marketing hpb seo plugin for WordPress hpbseo allows Reflecte...
CVE-2025-58939MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in highwarden Super Store Finder superstorefinder-wp allows Cross Site R...
CVE-2025-58711MEDIUM5.3Missing Authorization vulnerability in solwin Blog Designer PRO blog-designer-pro allows Accessing Functionality Not Pro...
CVE-2025-12058MEDIUM5.9The Keras.Model.load_model method, including when executed with the intended security mitigation safe_mode=True, is vuln...
CVE-2025-11702HIGH8.8GitLab has remediated an issue in EE affecting all versions from 17.1 before 18.3.5, 18.4 before 18.4.3, and 18.5 before...
CVE-2025-9544MEDIUM6.5The Doppler Forms WordPress plugin through 2.5.1 registers an AJAX action install_extension without verifying user capab...
CVE-2025-62776HIGH8.4The installer of WTW EAGLE (for Windows) 3.0.8.0 contains an issue with the DLL search path, which may lead to insecurel...
CVE-2025-49042MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooComm...
CVE-2025-11705MEDIUM6.5The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all vers...
CVE-2025-64296MEDIUM5.3Missing Authorization vulnerability in Facebook Facebook for WooCommerce facebook-for-woocommerce allows Exploiting Inco...
CVE-2025-64162Rejected reason: Not used
CVE-2025-64161Rejected reason: Not used
CVE-2025-64160Rejected reason: Not used
CVE-2025-64159Rejected reason: Not used
CVE-2025-64158Rejected reason: Not used
CVE-2025-57931MEDIUM5.3Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Popup box ays-popup-box allows Cross Site Request Forgery.Thi...
CVE-2025-4665CRITICAL9.6WordPress plugin Contact Form CFDB7 versions up to and including 1.3.2 are affected by a pre-authentication SQL injectio...
CVE-2025-64095CRITICAL9.8DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 1...
CVE-2025-64094MEDIUM5.4DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 1...
CVE-2025-62802MEDIUM4.3DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 1...
CVE-2025-62801HIGH7.8FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerabi...
CVE-2025-62800MEDIUM6.1FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0 have a reflected cross-site sc...
CVE-2025-62798MEDIUM5.4Sharp is a content management framework built for Laravel as a package. Prior to 9.11.1, a Cross-Site Scripting (XSS) vu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now