2025 CVE Vulnerabilities
45,209 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49920 | MEDIUM | 5.4 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in accessiBe Web Accessibility By accessiBe accessibe allows Exploiting Incorrectly ... |
| CVE-2025-49917 | MEDIUM | 4.4 | 0.2% | Oct 22, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Icegram Icegram Express Pro email-subscribers-premium allows Server ... |
| CVE-2025-49916 | HIGH | 8.6 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Accessing Functional... |
| CVE-2025-49915 | CRITICAL | 9.3 | 0.4% | Oct 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Al... |
| CVE-2025-49913 | MEDIUM | 5.3 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in CoSchedule CoSchedule coschedule-by-todaymade allows Exploiting Incorrectly Confi... |
| CVE-2025-49912 | MEDIUM | 5.9 | 0.3% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nks Email Subscrip... |
| CVE-2025-49911 | HIGH | 7.1 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpinstinct WooComm... |
| CVE-2025-49910 | HIGH | 8.2 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Accessing Functionality No... |
| CVE-2025-49908 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPClever WPC Count... |
| CVE-2025-49907 | MEDIUM | 4.3 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Exploiting Incorre... |
| CVE-2025-49906 | MEDIUM | 5.3 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in StellarWP WPComplete wpcomplete allows Accessing Functionality Not Properly Const... |
| CVE-2025-49903 | MEDIUM | 5.3 | 0.2% | Oct 22, 2025 | Missing Authorization vulnerability in bdthemes ZoloBlocks zoloblocks allows Exploiting Incorrectly Configured Access Co... |
| CVE-2025-49901 | CRITICAL | 9.8 | 0.7% | Oct 22, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-l... |
| CVE-2025-49899 | MEDIUM | 5.3 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in jjlemstra Whydonate wp-whydonate allows Accessing Functionality Not Properly Cons... |
| CVE-2025-49380 | CRITICAL | 9.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder ... |
| CVE-2025-49378 | HIGH | 8.5 | 0.4% | Oct 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Boo... |
| CVE-2025-49377 | MEDIUM | 6.3 | 0.2% | Oct 22, 2025 | Missing Authorization vulnerability in Themefic Hydra Booking hydra-booking allows Exploiting Incorrectly Configured Acc... |
| CVE-2025-49376 | MEDIUM | 5.3 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Accessing Functionality Not Properly Const... |
| CVE-2025-49374 | MEDIUM | 5.4 | 0.2% | Oct 22, 2025 | Server-Side Request Forgery (SSRF) vulnerability in captcha.eu Captcha.eu captcha-eu allows Server Side Request Forgery.... |
| CVE-2025-49373 | MEDIUM | 4.3 | 0.1% | Oct 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Evergreen Content Poster Evergreen Content Poster evergreen-content-p... |
| CVE-2025-49060 | CRITICAL | 10 | 0.4% | Oct 22, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Wastia wastia allows Upload a Web Shell ... |
| CVE-2025-48338 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-48106 | CRITICAL | 10 | 0.6% | Oct 22, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Clanora clanora allows Using Malicious F... |
| CVE-2025-48099 | MEDIUM | 4.7 | 0.2% | Oct 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Code Amp Search & Filter search-filter allows Cross Site Request Forg... |
| CVE-2025-48098 | HIGH | 7.1 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Mak... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now