2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63740 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | SQL Injection vulnerability in function getselectdataAjax in file inputAction.php in Xinhu Rainrock RockOA 2.7.0 allowin... |
| CVE-2025-63739 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | An issue was discovered in function phpinisaveAction in file webmain/system/cogini/coginiAction.php in Xinhu Rainrock Ro... |
| CVE-2025-63738 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | An issue was discovered in file index.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers to gain sensitive informatio... |
| CVE-2025-63737 | MEDIUM | 6.1 | 0.2% | Dec 9, 2025 | Cross-site scripting (XSS) vulnerability in function urltestAction in file cliAction.php in Xinhu Rainrock RockOA 2.7.0 ... |
| CVE-2025-12941 | MEDIUM | 5.7 | 0.2% | Dec 9, 2025 | Denial of Service Vulnerability in NETGEAR C6220 and C6230 (DOCSIS® 3.0 Two-in-one Cable Modem + WiFi Router) allows aut... |
| CVE-2025-9638 | MEDIUM | 4.8 | 0.2% | Dec 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Portabilis i-Educa... |
| CVE-2025-6924 | MEDIUM | 5.4 | 0.2% | Dec 9, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Soft... |
| CVE-2025-6923 | MEDIUM | 5.4 | 0.2% | Dec 9, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Soft... |
| CVE-2025-67599 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in WebToffee WebToffee eCommerce Marketing Automation decorator-woocommerce-email-cu... |
| CVE-2025-67598 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in PSM Plugins SupportCandy supportcandy allows Cross Site Request Forge... |
| CVE-2025-67597 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Missing Authorization vulnerability in Shahjahan Jewel Fluent Booking fluent-booking allows Exploiting Incorrectly Confi... |
| CVE-2025-67596 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Team Business Directory business-directory-plugin allows C... |
| CVE-2025-67595 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Quiz Maker quiz-maker allows Cross Site Request Forgery.This ... |
| CVE-2025-67594 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in ThimPress Thim Elementor Kit thim-elementor-kit allows... |
| CVE-2025-67593 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Stiofan UsersWP userswp allows Cross Site Request Forgery.This issue ... |
| CVE-2025-67592 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in Joe Dolson My Calendar my-calendar allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-67591 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in jegtheme JNews Paywall jnews-paywall allows Cross Site Request Forger... |
| CVE-2025-67590 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate FAQ ultimate-faqs allows Cross Site Request Forge... |
| CVE-2025-67589 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in WP Overnight WooCommerce PDF Invoices & Packing Slips woocommerce-pdf-invoices-pa... |
| CVE-2025-67588 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Confi... |
| CVE-2025-67587 | MEDIUM | 4.7 | 0.2% | Dec 9, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-fres... |
| CVE-2025-67586 | MEDIUM | 4.7 | 0.4% | Dec 9, 2025 | Missing Authorization vulnerability in Ronald Huereca Highlight and Share highlight-and-share allows Exploiting Incorrec... |
| CVE-2025-67585 | MEDIUM | 4.7 | 0.2% | Dec 9, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in flexmls Flexmls® IDX flexmls-idx allows Phishing.Th... |
| CVE-2025-67584 | MEDIUM | 5.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in rtCamp GoDAM godam allows Exploiting Incorrectly Configured Access Control Securi... |
| CVE-2025-67583 | MEDIUM | 5.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in Foysal Imran IDonate idonate allows Exploiting Incorrectly Configured Access Cont... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now