2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67436 | MEDIUM | 6.5 | 0.5% | Dec 22, 2025 | Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inj... |
| CVE-2025-67291 | MEDIUM | 6.1 | 0.2% | Dec 22, 2025 | A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute a... |
| CVE-2025-67290 | MEDIUM | 6.1 | 0.2% | Dec 22, 2025 | A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to e... |
| CVE-2025-65837 | MEDIUM | 5.4 | 0.1% | Dec 22, 2025 | PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in the Content Search module. |
| CVE-2025-65790 | MEDIUM | 6.1 | 0.2% | Dec 22, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in FuguHub 8.1 when serving SVG files through the /fs/ file ... |
| CVE-2025-26787 | MEDIUM | 4.7 | 0.1% | Dec 22, 2025 | An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CL... |
| CVE-2025-15033 | MEDIUM | 6.5 | 0.3% | Dec 22, 2025 | A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on si... |
| CVE-2025-65270 | MEDIUM | 6.1 | 0.2% | Dec 22, 2025 | Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC 3.0 and 2.2.3, allowing an unauthenticated remote ... |
| CVE-2025-68333 | MEDIUM | 5.5 | 0.1% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix possible deadlock in the deferred_ir... |
| CVE-2025-67443 | MEDIUM | 6.1 | 0.2% | Dec 22, 2025 | Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the lo... |
| CVE-2025-8460 | MEDIUM | 4.8 | 0.2% | Dec 22, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-54890 | MEDIUM | 4.8 | 0.2% | Dec 22, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-62880 | MEDIUM | 4.3 | 0.1% | Dec 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Kunal Custom 404 Pro custom-404-pro allows Cross Site Request Forgery... |
| CVE-2025-62107 | MEDIUM | 4.3 | 0.1% | Dec 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in PluginOps Feather Login Page feather-login-page allows Cross Site Req... |
| CVE-2025-62094 | MEDIUM | 6.5 | 0.1% | Dec 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidthemes Void El... |
| CVE-2025-8305 | MEDIUM | 6.5 | 0.1% | Dec 22, 2025 | An authenticated local user can obtain information that allows claiming security policy rules of another user due to sen... |
| CVE-2025-8304 | MEDIUM | 6.5 | 0.1% | Dec 22, 2025 | An authenticated local user can obtain information that allows claiming security policy rules of another user due to sen... |
| CVE-2025-15014 | MEDIUM | 6.3 | 0.2% | Dec 22, 2025 | A security flaw has been discovered in loganhong php loganSite up to c035fb5c3edd0b2a5e32fd4051cbbc9e61a31426. This affe... |
| CVE-2025-15013 | MEDIUM | 5.3 | 0.1% | Dec 22, 2025 | A vulnerability was identified in floooh sokol up to 5d11344150973f15e16d3ec4ee7550a73fb995e0. The impacted element is t... |
| CVE-2025-62926 | MEDIUM | 6.5 | 0.1% | Dec 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyDevs TempTool... |
| CVE-2025-62901 | MEDIUM | 6.5 | 0.1% | Dec 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tormorten WP Micro... |
| CVE-2025-62955 | MEDIUM | 4.3 | 0.2% | Dec 21, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HappyDevs TempTool [Show Cu... |
| CVE-2025-14991 | MEDIUM | 4.8 | 0.2% | Dec 21, 2025 | A weakness has been identified in Campcodes Complete Online Beauty Parlor Management System 1.0. The affected element is... |
| CVE-2025-13693 | MEDIUM | 6.4 | 0.2% | Dec 21, 2025 | The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Cust... |
| CVE-2025-13361 | MEDIUM | 4.3 | 0.1% | Dec 21, 2025 | The Web to SugarCRM Lead plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now