2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54748 | MEDIUM | 6.5 | 0.3% | Dec 18, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RomanCode MapSVG mapsvg ... |
| CVE-2025-54745 | MEDIUM | 6.5 | 0.3% | Dec 18, 2025 | Missing Authorization vulnerability in miniOrange miniOrange's Google Authenticator miniorange-2-factor-authentication a... |
| CVE-2025-54743 | MEDIUM | 5.8 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in mkscripts Download After Email download-after-email allows Exploiting Incorrectly... |
| CVE-2025-54741 | MEDIUM | 6.5 | 0.3% | Dec 18, 2025 | Missing Authorization vulnerability in Tyler Moore Super Blank super-blank allows Exploiting Incorrectly Configured Acce... |
| CVE-2025-49919 | MEDIUM | 5.8 | 0.2% | Dec 18, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in DigitalME eRoom eroom-zoom-meetings-webinar allows Re... |
| CVE-2025-49918 | MEDIUM | 5.9 | 0.3% | Dec 18, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikboo... |
| CVE-2025-49914 | MEDIUM | 6.5 | 0.3% | Dec 18, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in jetmonsters Restaurant Menu ... |
| CVE-2025-49902 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in A WP Life Login Page Customizer – Customizer Login Page, Admin Page, Custom Desig... |
| CVE-2025-49041 | MEDIUM | 6.5 | 0.3% | Dec 18, 2025 | Missing Authorization vulnerability in The African Boss Get Cash get-cash allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-14318 | MEDIUM | 4.3 | 0.3% | Dec 18, 2025 | Improper access checks in M-Files Server before 25.12.15491.7 allows users to download files through M-Files Web using W... |
| CVE-2025-13498 | MEDIUM | 4.3 | 0.4% | Dec 18, 2025 | The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions ... |
| CVE-2025-12976 | MEDIUM | 6.4 | 0.4% | Dec 18, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2025-10019 | MEDIUM | 6.5 | 0.4% | Dec 18, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in codepeople Contact Form Email contact-form-to-email al... |
| CVE-2025-68463 | MEDIUM | 4.9 | 0.3% | Dec 18, 2025 | Bio.Entrez in Biopython through 186 allows doctype XXE. |
| CVE-2025-47325 | MEDIUM | 5.5 | 0.1% | Dec 18, 2025 | Information disclosure while processing system calls with invalid parameters. |
| CVE-2025-47319 | MEDIUM | 6.7 | 0.1% | Dec 18, 2025 | Information disclosure while exposing internal TA-to-TA communication APIs to HLOS |
| CVE-2025-68461 | MEDIUM | 6.1 | 19.8% | Dec 18, 2025 | Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the ani... |
| CVE-2025-12885 | MEDIUM | 6.4 | 0.2% | Dec 18, 2025 | The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-... |
| CVE-2025-68429 | MEDIUM | 5.3 | 0.2% | Dec 17, 2025 | Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present ... |
| CVE-2025-68401 | MEDIUM | 4.8 | 0.2% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Prior to version 6.0.0, the application stores user-supplied HTML/... |
| CVE-2025-68399 | MEDIUM | 5.4 | 0.2% | Dec 17, 2025 | ChurchCRM is an open-source church management system. In versions prior to 6.5.4, there is a Stored Cross-Site Scripting... |
| CVE-2025-68275 | MEDIUM | 4.8 | 0.2% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a stored cross-site scripting vulnera... |
| CVE-2025-67876 | MEDIUM | 5.4 | 0.2% | Dec 17, 2025 | ChurchCRM is an open-source church management system. A stored cross-site scripting (XSS) vulnerability exists in Church... |
| CVE-2025-67875 | MEDIUM | 5.4 | 0.2% | Dec 17, 2025 | ChurchCRM is an open-source church management system. A privilege escalation vulnerability exists in ChurchCRM prior to ... |
| CVE-2025-67794 | MEDIUM | 6.1 | 0.1% | Dec 17, 2025 | An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 before 24.2.8, and 25.1 before 25.1.6. Directories and fi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now