2025 CVE Vulnerabilities
45,322 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11220 | MEDIUM | 6.4 | 0.2% | Dec 16, 2025 | The Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Text Path widget in all... |
| CVE-2025-0836 | MEDIUM | 6.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in Milestone Systems XProtect VMS allows users with read-only access to Management S... |
| CVE-2025-68088 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Huger for Elementor huger-elementor allows Exploiting Incorrectly Confi... |
| CVE-2025-68087 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Modalier for Elementor modalier-elementor allows Exploiting Incorrectly... |
| CVE-2025-68086 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Reformer for Elementor reformer-elementor allows Exploiting Incorrectly... |
| CVE-2025-68085 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Buttoner for Elementor buttoner-elementor allows Exploiting Incorrectly... |
| CVE-2025-68084 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in Nitesh Ultimate Auction ultimate-auction allows Exploiting Incorrectly Configure... |
| CVE-2025-68083 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Meks Meks Quick Plugin Disabler meks-quick-plugin-disabler allows Cro... |
| CVE-2025-68082 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in SEMrush CY LTD Semrush Content Toolkit semrush-contentshake allows Cr... |
| CVE-2025-68080 | MEDIUM | 6.5 | 0.1% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal User Av... |
| CVE-2025-68079 | MEDIUM | 6.5 | 0.1% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNectar Salien... |
| CVE-2025-68078 | MEDIUM | 6.5 | 0.1% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNectar Salien... |
| CVE-2025-68077 | MEDIUM | 6.5 | 0.1% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Select-Themes Stoc... |
| CVE-2025-68076 | MEDIUM | 6.5 | 0.1% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Select-Themes Stoc... |
| CVE-2025-68071 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in g5theme Essential Real Estate essential-real-estate al... |
| CVE-2025-68070 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vektor,Inc. VK Goo... |
| CVE-2025-67989 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Server-Side Request Forgery (SSRF) vulnerability in LMPixels Kerge kerge allows Server Side Request Forgery.This issue a... |
| CVE-2025-67986 | MEDIUM | 5.9 | 0.2% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Barn2 Plugins Docu... |
| CVE-2025-67985 | MEDIUM | 5.3 | 0.3% | Dec 16, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Barn2 Plugins Document Library Lite document-library-l... |
| CVE-2025-67983 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visit... |
| CVE-2025-67976 | MEDIUM | 6.5 | 0.3% | Dec 16, 2025 | Missing Authorization vulnerability in Bob Watu Quiz watu allows Exploiting Incorrectly Configured Access Control Securi... |
| CVE-2025-67965 | MEDIUM | 5.3 | 0.3% | Dec 16, 2025 | Missing Authorization vulnerability in favethemes Homey Core homey-core allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-67951 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Addo... |
| CVE-2025-67948 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in SendPulse SendPulse Email Ma... |
| CVE-2025-67929 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Exploitin... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now