2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48253 | MEDIUM | 5.4 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Free Shi... |
| CVE-2025-48252 | MEDIUM | 5.4 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Back But... |
| CVE-2025-48251 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Addition... |
| CVE-2025-48250 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Coupons ... |
| CVE-2025-48249 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory EAN for ... |
| CVE-2025-48248 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Sitewide... |
| CVE-2025-48247 | MEDIUM | 4.3 | 0.3% | May 19, 2025 | Missing Authorization vulnerability in Blair Williams Shortlinks by Pretty Links pretty-link allows Exploiting Incorrect... |
| CVE-2025-48246 | MEDIUM | 5.4 | 0.3% | May 19, 2025 | Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly C... |
| CVE-2025-48244 | MEDIUM | 5.9 | 0.3% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclu... |
| CVE-2025-48243 | MEDIUM | 4.3 | 0.1% | May 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in sminozzi reCAPTCHA for all recaptcha-for-all allows Cross Site Reques... |
| CVE-2025-48242 | MEDIUM | 6.5 | 0.3% | May 19, 2025 | Missing Authorization vulnerability in wpWax Legal Pages legal-pages allows Exploiting Incorrectly Configured Access Con... |
| CVE-2025-48240 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Cost of ... |
| CVE-2025-48239 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Product ... |
| CVE-2025-48237 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist... |
| CVE-2025-48235 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bogdan Bendziukov ... |
| CVE-2025-48234 | MEDIUM | 6.5 | 0.3% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Blocks Ul... |
| CVE-2025-48232 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xpro Xpro Addons F... |
| CVE-2025-43714 | MEDIUM | 6.5 | 0.4% | May 19, 2025 | The ChatGPT system through 2025-03-30 performs inline rendering of SVG documents (instead of, for example, rendering the... |
| CVE-2025-3908 | MEDIUM | 6.2 | 0.2% | May 19, 2025 | The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlink... |
| CVE-2025-44108 | MEDIUM | 4.8 | 0.3% | May 19, 2025 | A stored Cross-Site Scripting (XSS) vulnerability exists in the administration panel of Flatpress CMS before 1.4 via the... |
| CVE-2025-28371 | MEDIUM | 6.5 | 0.4% | May 19, 2025 | EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function. The de... |
| CVE-2025-32999 | MEDIUM | 5.4 | 0.2% | May 19, 2025 | Cross-site scripting vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and prior to Ver. 3.0.47. This iss... |
| CVE-2025-2561 | MEDIUM | 4.8 | 0.2% | May 19, 2025 | The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2025-2560 | MEDIUM | 4.8 | 0.2% | May 19, 2025 | The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2025-2524 | MEDIUM | 4.8 | 0.3% | May 19, 2025 | The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow hig... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now