2025 CVE Vulnerabilities

45,251 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53340MEDIUM5.3Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive...
CVE-2025-53303HIGH8.8Deserialization of Untrusted Data vulnerability in ThemeMove ThemeMove Core thememove-core allows Object Injection.This ...
CVE-2025-53291MEDIUM5.4Missing Authorization vulnerability in spoddev2021 Spreadconnect wc-spod.This issue affects Spreadconnect: from n/a thro...
CVE-2025-49860MEDIUM5.3Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support.This issue affects Majestic Su...
CVE-2025-49734HIGH7Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker ...
CVE-2025-49692HIGH7.8Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges local...
CVE-2025-49430HIGH7.2Server-Side Request Forgery (SSRF) vulnerability in FWDesign Ultimate Video Player fwduvp allows Server Side Request For...
CVE-2025-48101HIGH8.8Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection....
CVE-2025-47997MEDIUM5.3Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an auth...
CVE-2025-47695HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-47694HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in solwin Blog Design...
CVE-2025-47579HIGH8.1Deserialization of Untrusted Data vulnerability in ThemeGoods Photography photography allows Object Injection.This issue...
CVE-2025-47571HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-47570HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in villatheme WooComm...
CVE-2025-47569CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPSwings WooCommer...
CVE-2025-47437MEDIUM6.4Server-Side Request Forgery (SSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue af...
CVE-2025-39553MEDIUM4.3Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a th...
CVE-2025-39541MEDIUM6.5Missing Authorization vulnerability in Roland Murg WP Simple Booking Calendar wp-simple-booking-calendar.This issue affe...
CVE-2025-39523MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in GoodBarber GoodBarber goodbarber.This issue affects...
CVE-2025-32689HIGH7.5Improper Validation of Specified Quantity in Input vulnerability in Convers Lab WP SmartPay smartpay.This issue affects ...
CVE-2025-32688MEDIUM5.4Missing Authorization vulnerability in Nebojsa Target Video Easy Publish brid-video-easy-publish.This issue affects Targ...
CVE-2025-32486CRITICAL9.8Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material Dashboard material-dashboard.T...
CVE-2025-30875MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alexandre Froger W...
CVE-2025-9872HIGH8.8Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthe...
CVE-2025-9712HIGH8.8Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthe...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now