2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-32288HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-31425HIGH7.5Missing Authorization vulnerability in kamleshyadav WP Lead Capturing Pages leadcapture allows Exploiting Incorrectly Co...
CVE-2025-31007HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alvind Billplz Add...
CVE-2025-30998HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rico Macchi WP Lin...
CVE-2025-30993MEDIUM6.5Missing Authorization vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customize...
CVE-2025-30639HIGH7.5Missing Authorization vulnerability in ThemeAtelier IDonatePro idonate-pro allows Exploiting Incorrectly Configured Acce...
CVE-2025-30635HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-30626HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Multi...
CVE-2025-29014HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomIt FoodMenu al...
CVE-2025-28999HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomIt WooCommerce...
CVE-2025-28987MEDIUM6.4Server-Side Request Forgery (SSRF) vulnerability in PressForward PressForward pressforward allows Server Side Request Fo...
CVE-2025-28979CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-28975HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in redqteam Alike - W...
CVE-2025-28962MEDIUM6.5Missing Authorization vulnerability in stefanoai Advanced Google Universal Analytics advanced-google-universal-analytics...
CVE-2025-25174CRITICAL10Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-25172HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-24775CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms forms-by-made-it allows Upload a Web Sh...
CVE-2025-24766HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-8956HIGH8.8A vulnerability was found in D-Link DIR‑818L up to 1.05B01. This issue affects the function getenv of the file /htdocs/c...
CVE-2025-8955CRITICAL9.8A vulnerability has been found in PHPGurukul Hospital Management System 4.0. This vulnerability affects unknown code of ...
CVE-2025-8943CRITICAL9.8The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Se...
CVE-2025-8047CRITICAL9.8The disable-right-click-powered-by-pixterme through v1.2 and pixter-image-digital-license thtough v1.0 WordPress plugins...
CVE-2025-7761MEDIUM5.1Lepszy BIP is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in index.php form in one of ...
CVE-2025-55346CRITICAL9.8User-controlled input flows to an unsafe implementation of a dynamic Function constructor, allowing network attackers to...
CVE-2025-8954CRITICAL9.8A vulnerability was identified in PHPGurukul Hospital Management System 4.0. This affects an unknown part of the file /a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now