2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-68986CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Miion miion allows Upload a Web Shell to a W...
CVE-2025-68913HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68912HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Harmonic Design HDForms ...
CVE-2025-68911MEDIUM6.5Missing Authorization vulnerability in solacewp Solace solace allows Exploiting Incorrectly Configured Access Control Se...
CVE-2025-68910CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogzee blogzee allows Using Malicious File...
CVE-2025-68909CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogistic blogistic allows Using Malicious ...
CVE-2025-68908HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68907HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Hostme v2 ho...
CVE-2025-68906HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jegtheme JNews - V...
CVE-2025-68905HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68904HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jegtheme JNews - F...
CVE-2025-68903HIGH8.8Deserialization of Untrusted Data vulnerability in AivahThemes Anona anona allows Object Injection.This issue affects An...
CVE-2025-68902HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Anona anona ...
CVE-2025-68901HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Anona anona ...
CVE-2025-68900MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold allo...
CVE-2025-68899HIGH8.8Deserialization of Untrusted Data vulnerability in designthemes Vivagh vivagh allows Object Injection.This issue affects...
CVE-2025-68898MEDIUM5.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cjjparadoxmax Syne...
CVE-2025-68896MEDIUM6.5Missing Authorization vulnerability in vrpr WDV One Page Docs wdv-one-page-docs allows Exploiting Incorrectly Configured...
CVE-2025-68894HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shoutoutglobal Sho...
CVE-2025-68884HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arevico WP Simple ...
CVE-2025-68883HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extremeidea bidorb...
CVE-2025-68882HIGH7.5Missing Authorization vulnerability in Scalenut Scalenut scalenut allows Exploiting Incorrectly Configured Access Contro...
CVE-2025-68881HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal AppExpe...
CVE-2025-68871HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in noCreativity Doood...
CVE-2025-68869CRITICAL9.8Incorrect Privilege Assignment vulnerability in LazyCoders LLC LazyTasks lazytasks-project-task-management allows Privil...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now