2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68512 | MEDIUM | 6.5 | 0.1% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativeinteractiv... |
| CVE-2025-68511 | MEDIUM | 6.5 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Jegstudio Gutenverse Form gutenverse-form allows Exploiting Incorrectly Configure... |
| CVE-2025-68509 | MEDIUM | 4.7 | 0.5% | Dec 24, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Jeff Starr User Submitted Posts user-submitted-post... |
| CVE-2025-68508 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Brave Brave brave-popup-builder allows Exploiting Incorrectly Configured Access C... |
| CVE-2025-68505 | MEDIUM | 5.3 | 0.3% | Dec 24, 2025 | Missing Authorization vulnerability in icc0rz H5P h5p allows Exploiting Incorrectly Configured Access Control Security L... |
| CVE-2025-68500 | MEDIUM | 4.9 | 0.2% | Dec 24, 2025 | Server-Side Request Forgery (SSRF) vulnerability in bdthemes Prime Slider – Addons For Elementor bdthemes-prime-slider-l... |
| CVE-2025-68497 | MEDIUM | 5.9 | 0.3% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force A... |
| CVE-2025-68494 | MEDIUM | 5.3 | 0.3% | Dec 24, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Leap13 Premium Addons for El... |
| CVE-2025-67633 | MEDIUM | 5.9 | 0.2% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brownbagmarketing ... |
| CVE-2025-67632 | MEDIUM | 5.9 | 0.2% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Plugin Factory... |
| CVE-2025-67631 | MEDIUM | 5.9 | 0.2% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ecommerce Platform... |
| CVE-2025-67630 | MEDIUM | 5.9 | 0.2% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webheadcoder WH Tw... |
| CVE-2025-67629 | MEDIUM | 5.9 | 0.2% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basticom Basticom ... |
| CVE-2025-67628 | MEDIUM | 5.9 | 0.2% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AMP-MODE Review Di... |
| CVE-2025-67627 | MEDIUM | 5.9 | 0.2% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TouchOfTech Draft ... |
| CVE-2025-67625 | MEDIUM | 4.3 | 0.1% | Dec 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in tmtraderunner Trade Runner traderunner allows Cross Site Request Forg... |
| CVE-2025-67623 | MEDIUM | 5.4 | 0.2% | Dec 24, 2025 | Server-Side Request Forgery (SSRF) vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Server Side Reques... |
| CVE-2025-67621 | MEDIUM | 4.3 | 0.2% | Dec 24, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in 10up Eight Day Week Print Wo... |
| CVE-2025-68725 | MEDIUM | 5.5 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: Do not let BPF test infra emit invalid GSO typ... |
| CVE-2025-68365 | MEDIUM | 5.5 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize allocated memory before use K... |
| CVE-2025-68358 | MEDIUM | 5.5 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix racy bitfield write in btrfs_clear_space... |
| CVE-2025-68351 | MEDIUM | 5.5 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: exfat: fix refcount leak in exfat_find Fix refcoun... |
| CVE-2025-64641 | MEDIUM | 4.1 | 0.1% | Dec 24, 2025 | Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post ... |
| CVE-2025-13767 | MEDIUM | 4.3 | 0.2% | Dec 24, 2025 | Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user ch... |
| CVE-2025-13407 | MEDIUM | 6.8 | 0.3% | Dec 24, 2025 | The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files throug... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now