2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68986 | CRITICAL | 9.9 | 0.4% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Miion miion allows Upload a Web Shell to a W... |
| CVE-2025-68913 | HIGH | 7.5 | 0.5% | Jan 22, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68912 | HIGH | 8.6 | 0.5% | Jan 22, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Harmonic Design HDForms ... |
| CVE-2025-68911 | MEDIUM | 6.5 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in solacewp Solace solace allows Exploiting Incorrectly Configured Access Control Se... |
| CVE-2025-68910 | CRITICAL | 9.9 | 0.5% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogzee blogzee allows Using Malicious File... |
| CVE-2025-68909 | CRITICAL | 9.9 | 0.5% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogistic blogistic allows Using Malicious ... |
| CVE-2025-68908 | HIGH | 8.1 | 0.4% | Jan 22, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68907 | HIGH | 7.5 | 0.4% | Jan 22, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Hostme v2 ho... |
| CVE-2025-68906 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jegtheme JNews - V... |
| CVE-2025-68905 | HIGH | 7.5 | 0.4% | Jan 22, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68904 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jegtheme JNews - F... |
| CVE-2025-68903 | HIGH | 8.8 | 0.4% | Jan 22, 2026 | Deserialization of Untrusted Data vulnerability in AivahThemes Anona anona allows Object Injection.This issue affects An... |
| CVE-2025-68902 | HIGH | 7.5 | 0.4% | Jan 22, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Anona anona ... |
| CVE-2025-68901 | HIGH | 8.6 | 0.5% | Jan 22, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Anona anona ... |
| CVE-2025-68900 | MEDIUM | 6.5 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold allo... |
| CVE-2025-68899 | HIGH | 8.8 | 0.4% | Jan 22, 2026 | Deserialization of Untrusted Data vulnerability in designthemes Vivagh vivagh allows Object Injection.This issue affects... |
| CVE-2025-68898 | MEDIUM | 5.8 | 0.1% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cjjparadoxmax Syne... |
| CVE-2025-68896 | MEDIUM | 6.5 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in vrpr WDV One Page Docs wdv-one-page-docs allows Exploiting Incorrectly Configured... |
| CVE-2025-68894 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shoutoutglobal Sho... |
| CVE-2025-68884 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arevico WP Simple ... |
| CVE-2025-68883 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extremeidea bidorb... |
| CVE-2025-68882 | HIGH | 7.5 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in Scalenut Scalenut scalenut allows Exploiting Incorrectly Configured Access Contro... |
| CVE-2025-68881 | HIGH | 8.5 | 0.3% | Jan 22, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal AppExpe... |
| CVE-2025-68871 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in noCreativity Doood... |
| CVE-2025-68869 | CRITICAL | 9.8 | 0.4% | Jan 22, 2026 | Incorrect Privilege Assignment vulnerability in LazyCoders LLC LazyTasks lazytasks-project-task-management allows Privil... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now