2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47563 | MEDIUM | 5.3 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in villatheme CURCY woocommerce-multi-currency allows Accessing Functionality Not Pr... |
| CVE-2025-47562 | MEDIUM | 5.3 | 0.3% | May 16, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG mapsvg allows Code Injection... |
| CVE-2025-47560 | MEDIUM | 5 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in RomanCode MapSVG mapsvg allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2025-47557 | MEDIUM | 6.5 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RomanCode MapSVG m... |
| CVE-2025-47556 | MEDIUM | 5.4 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for WordPress css3_web_pricing_tables_gr... |
| CVE-2025-47534 | MEDIUM | 4.3 | 0.2% | May 16, 2025 | Missing Authorization vulnerability in ValvePress Wordpress Auto Spinner wp-auto-spinner allows Exploiting Incorrectly C... |
| CVE-2025-46464 | MEDIUM | 6.5 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scripteo Ads Pro a... |
| CVE-2025-39511 | MEDIUM | 4.3 | 0.2% | May 16, 2025 | Missing Authorization vulnerability in ValvePress Pinterest Automatic Pin wp-pinterest-automatic allows Exploiting Incor... |
| CVE-2025-39509 | MEDIUM | 5.4 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNcode TNC Fli... |
| CVE-2025-32299 | MEDIUM | 4.3 | 0.3% | May 16, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Themovation QuickCal - Appoi... |
| CVE-2025-32296 | MEDIUM | 5.3 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Exploiting Inc... |
| CVE-2025-32295 | MEDIUM | 4.3 | 0.2% | May 16, 2025 | Missing Authorization vulnerability in wordpresschef Salon Booking Pro salon-booking-plugin-pro-cc allows Exploiting Inc... |
| CVE-2025-32245 | MEDIUM | 6.5 | 0.1% | May 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Chaser324 Featured Posts Scroll featured-posts-scroll allows Stored X... |
| CVE-2025-32180 | MEDIUM | 6.5 | 0.2% | May 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojofywp Product C... |
| CVE-2025-31923 | MEDIUM | 5.4 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in QuanticaLabs CSS3 Accordions for WordPress css3_accordions allows Exploiting Inco... |
| CVE-2025-31921 | MEDIUM | 4.3 | 0.1% | May 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Ultimate Tours Builder WP_UltimateToursBuilder allows Cross... |
| CVE-2025-31915 | MEDIUM | 5.4 | 0.1% | May 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder pixel... |
| CVE-2025-31639 | MEDIUM | 4.3 | 0.2% | May 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in themeton Spare allows Cross Site Request Forgery. This issue affects ... |
| CVE-2025-31630 | MEDIUM | 5.3 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in themeton The Business allows Exploiting Incorrectly Configured Access Control Sec... |
| CVE-2025-31071 | MEDIUM | 5.3 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Exploiting Incorrectly Con... |
| CVE-2025-31068 | MEDIUM | 4.3 | 0.2% | May 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in themeton Seven Stars allows Cross Site Request Forgery. This issue af... |
| CVE-2025-31066 | MEDIUM | 5.3 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in themeton Acerola acerola allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2025-31065 | MEDIUM | 5.3 | 0.3% | May 16, 2025 | Missing Authorization vulnerability in themeton Rozario allows Exploiting Incorrectly Configured Access Control Security... |
| CVE-2025-31063 | MEDIUM | 4.3 | 0.2% | May 16, 2025 | Missing Authorization vulnerability in redqteam Wishlist wishlist allows Exploiting Incorrectly Configured Access Contro... |
| CVE-2025-31062 | MEDIUM | 4.3 | 0.3% | May 16, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in redqteam Wishlist wishlist a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now