2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69312 | CRITICAL | 9.1 | 0.3% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows... |
| CVE-2025-69311 | HIGH | 7.6 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in Broadstreet Broadstreet Ads broadstreet allows Exploiting Incorrectly Configured ... |
| CVE-2025-69300 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor allows Exploitin... |
| CVE-2025-69293 | HIGH | 8.8 | 0.3% | Jan 22, 2026 | Incorrect Privilege Assignment vulnerability in e-plugins Final User final-user allows Privilege Escalation.This issue a... |
| CVE-2025-69292 | HIGH | 8.8 | 0.3% | Jan 22, 2026 | Incorrect Privilege Assignment vulnerability in e-plugins WP Membership wp-membership allows Privilege Escalation.This i... |
| CVE-2025-69193 | HIGH | 7.3 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in e-plugins WP Membership wp-membership allows Exploiting Incorrectly Configured Ac... |
| CVE-2025-69192 | HIGH | 7.3 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in e-plugins Real Estate Pro real-estate-pro allows Exploiting Incorrectly Configure... |
| CVE-2025-69191 | HIGH | 7.3 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in e-plugins ListingHub listinghub allows Exploiting Incorrectly Configured Access C... |
| CVE-2025-69190 | HIGH | 7.3 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in e-plugins Listihub listihub allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2025-69188 | HIGH | 7.3 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in e-plugins fitness-trainer fitness-trainer allows Exploiting Incorrectly Configure... |
| CVE-2025-69187 | HIGH | 7.3 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in e-plugins Final User final-user allows Exploiting Incorrectly Configured Access C... |
| CVE-2025-69186 | HIGH | 7.3 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in e-plugins Hospital Doctor Directory hospital-doctor-directory allows Exploiting I... |
| CVE-2025-69185 | HIGH | 7.3 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in e-plugins Hotel Listing hotel-listing allows Exploiting Incorrectly Configured Ac... |
| CVE-2025-69184 | HIGH | 7.3 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in e-plugins Institutions Directory institutions-directory allows Exploiting Incorre... |
| CVE-2025-69183 | HIGH | 8.8 | 0.4% | Jan 22, 2026 | Incorrect Privilege Assignment vulnerability in e-plugins Hospital Doctor Directory hospital-doctor-directory allows Pri... |
| CVE-2025-69182 | HIGH | 8.8 | 0.4% | Jan 22, 2026 | Incorrect Privilege Assignment vulnerability in e-plugins Institutions Directory institutions-directory allows Privilege... |
| CVE-2025-69181 | HIGH | 7.3 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in e-plugins Lawyer Directory lawyer-directory allows Exploiting Incorrectly Configu... |
| CVE-2025-69180 | HIGH | 8.5 | 0.3% | Jan 22, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themepassion Ultra... |
| CVE-2025-69102 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Boopathi Rajan WP ... |
| CVE-2025-69101 | CRITICAL | 9.8 | 0.5% | Jan 22, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Workreap Core workreap_core allows ... |
| CVE-2025-69100 | HIGH | 8.1 | 0.5% | Jan 22, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-69099 | HIGH | 8.8 | 0.4% | Jan 22, 2026 | Deserialization of Untrusted Data vulnerability in fuelthemes North north-wp allows Object Injection.This issue affects ... |
| CVE-2025-69098 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWave Hide My WP ... |
| CVE-2025-69097 | HIGH | 8.6 | 0.5% | Jan 22, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in VibeThemes WPLMS wplms_p... |
| CVE-2025-69095 | MEDIUM | 6.5 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in designthemes Reservation Plugin dt-reservation-plugin allows Exploiting Incorrect... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now