2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64270 | MEDIUM | 6.5 | 0.3% | Dec 18, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in masteriyo Masteriyo - LMS le... |
| CVE-2025-64225 | MEDIUM | 6.5 | 0.3% | Dec 18, 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in colabrio Stockie Extra st... |
| CVE-2025-64192 | MEDIUM | 6.3 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in 8theme XStore xstore allows Exploiting Incorrectly Configured Access Control Secu... |
| CVE-2025-63039 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in CridioStudio ListingPro listingpro allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-60088 | MEDIUM | 6.5 | 0.3% | Dec 18, 2025 | Missing Authorization vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Exploiting Incor... |
| CVE-2025-60070 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in The4 Molla molla allows Code Injection.This i... |
| CVE-2025-60068 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in javothemes Javo Core javo-core allows Code In... |
| CVE-2025-54748 | MEDIUM | 6.5 | 0.3% | Dec 18, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RomanCode MapSVG mapsvg ... |
| CVE-2025-54745 | MEDIUM | 6.5 | 0.3% | Dec 18, 2025 | Missing Authorization vulnerability in miniOrange miniOrange's Google Authenticator miniorange-2-factor-authentication a... |
| CVE-2025-54743 | MEDIUM | 5.8 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in mkscripts Download After Email download-after-email allows Exploiting Incorrectly... |
| CVE-2025-54741 | MEDIUM | 6.5 | 0.3% | Dec 18, 2025 | Missing Authorization vulnerability in Tyler Moore Super Blank super-blank allows Exploiting Incorrectly Configured Acce... |
| CVE-2025-49919 | MEDIUM | 5.8 | 0.2% | Dec 18, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in DigitalME eRoom eroom-zoom-meetings-webinar allows Re... |
| CVE-2025-49918 | MEDIUM | 5.9 | 0.3% | Dec 18, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikboo... |
| CVE-2025-49914 | MEDIUM | 6.5 | 0.3% | Dec 18, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in jetmonsters Restaurant Menu ... |
| CVE-2025-49902 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in A WP Life Login Page Customizer – Customizer Login Page, Admin Page, Custom Desig... |
| CVE-2025-49041 | MEDIUM | 6.5 | 0.3% | Dec 18, 2025 | Missing Authorization vulnerability in The African Boss Get Cash get-cash allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-14318 | MEDIUM | 4.3 | 0.3% | Dec 18, 2025 | Improper access checks in M-Files Server before 25.12.15491.7 allows users to download files through M-Files Web using W... |
| CVE-2025-13498 | MEDIUM | 4.3 | 0.4% | Dec 18, 2025 | The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions ... |
| CVE-2025-12976 | MEDIUM | 6.4 | 0.4% | Dec 18, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2025-10019 | MEDIUM | 6.5 | 0.4% | Dec 18, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in codepeople Contact Form Email contact-form-to-email al... |
| CVE-2025-68463 | MEDIUM | 4.9 | 0.3% | Dec 18, 2025 | Bio.Entrez in Biopython through 186 allows doctype XXE. |
| CVE-2025-47325 | MEDIUM | 5.5 | 0.1% | Dec 18, 2025 | Information disclosure while processing system calls with invalid parameters. |
| CVE-2025-47319 | MEDIUM | 6.7 | 0.1% | Dec 18, 2025 | Information disclosure while exposing internal TA-to-TA communication APIs to HLOS |
| CVE-2025-68461 | MEDIUM | 6.1 | 19.8% | Dec 18, 2025 | Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the ani... |
| CVE-2025-12885 | MEDIUM | 6.4 | 0.2% | Dec 18, 2025 | The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now