2025 CVE Vulnerabilities
45,209 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49948 | HIGH | 7.1 | 0.3% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad Awais WP Sup... |
| CVE-2025-49947 | HIGH | 7.1 | 0.3% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendons WooComme... |
| CVE-2025-49946 | HIGH | 7.1 | 0.3% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cynob IT Consultan... |
| CVE-2025-49945 | HIGH | 7.1 | 0.3% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kylegetson Shortco... |
| CVE-2025-49944 | HIGH | 7.1 | 0.3% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jonatan Jumbert WP... |
| CVE-2025-49940 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Fusion... |
| CVE-2025-49939 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElem... |
| CVE-2025-49938 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngi... |
| CVE-2025-49937 | MEDIUM | 4.3 | 0.2% | Oct 22, 2025 | Missing Authorization vulnerability in Syed Balkhi Smash Balloon Social Post Feed custom-facebook-feed allows Exploiting... |
| CVE-2025-49936 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xtemos WoodMart wo... |
| CVE-2025-49935 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49934 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBloc... |
| CVE-2025-49933 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlog... |
| CVE-2025-49932 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlog... |
| CVE-2025-49931 | CRITICAL | 9.3 | 0.4% | Oct 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetSear... |
| CVE-2025-49930 | HIGH | 7.1 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSear... |
| CVE-2025-49929 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Blocks Ul... |
| CVE-2025-49928 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetWooB... |
| CVE-2025-49927 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetWooB... |
| CVE-2025-49926 | HIGH | 7.2 | 0.2% | Oct 22, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Laborator Kalium kalium allows Code Injection... |
| CVE-2025-49925 | HIGH | 7.5 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constra... |
| CVE-2025-49924 | HIGH | 7.2 | 0.4% | Oct 22, 2025 | Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privil... |
| CVE-2025-49923 | MEDIUM | 5.9 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Serio... |
| CVE-2025-49922 | MEDIUM | 4.3 | 0.2% | Oct 22, 2025 | Missing Authorization vulnerability in etruel WPeMatico RSS Feed Fetcher wpematico allows Exploiting Incorrectly Configu... |
| CVE-2025-49921 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now