2025 CVE Vulnerabilities
45,251 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53340 | MEDIUM | 5.3 | 0.3% | Sep 9, 2025 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive... |
| CVE-2025-53303 | HIGH | 8.8 | 0.3% | Sep 9, 2025 | Deserialization of Untrusted Data vulnerability in ThemeMove ThemeMove Core thememove-core allows Object Injection.This ... |
| CVE-2025-53291 | MEDIUM | 5.4 | 0.2% | Sep 9, 2025 | Missing Authorization vulnerability in spoddev2021 Spreadconnect wc-spod.This issue affects Spreadconnect: from n/a thro... |
| CVE-2025-49860 | MEDIUM | 5.3 | 0.3% | Sep 9, 2025 | Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support.This issue affects Majestic Su... |
| CVE-2025-49734 | HIGH | 7 | 0.3% | Sep 9, 2025 | Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker ... |
| CVE-2025-49692 | HIGH | 7.8 | 0.3% | Sep 9, 2025 | Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges local... |
| CVE-2025-49430 | HIGH | 7.2 | 0.2% | Sep 9, 2025 | Server-Side Request Forgery (SSRF) vulnerability in FWDesign Ultimate Video Player fwduvp allows Server Side Request For... |
| CVE-2025-48101 | HIGH | 8.8 | 0.3% | Sep 9, 2025 | Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection.... |
| CVE-2025-47997 | MEDIUM | 5.3 | 0.8% | Sep 9, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an auth... |
| CVE-2025-47695 | HIGH | 7.5 | 0.5% | Sep 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47694 | HIGH | 7.1 | 0.2% | Sep 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in solwin Blog Design... |
| CVE-2025-47579 | HIGH | 8.1 | 0.3% | Sep 9, 2025 | Deserialization of Untrusted Data vulnerability in ThemeGoods Photography photography allows Object Injection.This issue... |
| CVE-2025-47571 | HIGH | 7.5 | 0.4% | Sep 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47570 | HIGH | 7.1 | 0.2% | Sep 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in villatheme WooComm... |
| CVE-2025-47569 | CRITICAL | 9.3 | 0.6% | Sep 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPSwings WooCommer... |
| CVE-2025-47437 | MEDIUM | 6.4 | 0.2% | Sep 9, 2025 | Server-Side Request Forgery (SSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue af... |
| CVE-2025-39553 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a th... |
| CVE-2025-39541 | MEDIUM | 6.5 | 0.3% | Sep 9, 2025 | Missing Authorization vulnerability in Roland Murg WP Simple Booking Calendar wp-simple-booking-calendar.This issue affe... |
| CVE-2025-39523 | MEDIUM | 4.7 | 0.2% | Sep 9, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in GoodBarber GoodBarber goodbarber.This issue affects... |
| CVE-2025-32689 | HIGH | 7.5 | 0.3% | Sep 9, 2025 | Improper Validation of Specified Quantity in Input vulnerability in Convers Lab WP SmartPay smartpay.This issue affects ... |
| CVE-2025-32688 | MEDIUM | 5.4 | 0.2% | Sep 9, 2025 | Missing Authorization vulnerability in Nebojsa Target Video Easy Publish brid-video-easy-publish.This issue affects Targ... |
| CVE-2025-32486 | CRITICAL | 9.8 | 0.3% | Sep 9, 2025 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material Dashboard material-dashboard.T... |
| CVE-2025-30875 | MEDIUM | 5.9 | 0.2% | Sep 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alexandre Froger W... |
| CVE-2025-9872 | HIGH | 8.8 | 13.5% | Sep 9, 2025 | Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthe... |
| CVE-2025-9712 | HIGH | 8.8 | 20.5% | Sep 9, 2025 | Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthe... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now