2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68034 | CRITICAL | 9.3 | 0.4% | Jan 22, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® Cleve... |
| CVE-2025-68030 | HIGH | 7.2 | 0.2% | Jan 22, 2026 | Server-Side Request Forgery (SSRF) vulnerability in WP Messiah Frontis Blocks frontis-blocks allows Server Side Request ... |
| CVE-2025-68027 | HIGH | 7.3 | 0.3% | Jan 22, 2026 | Incorrect Privilege Assignment vulnerability in Themefic Hydra Booking hydra-booking allows Privilege Escalation.This is... |
| CVE-2025-68020 | MEDIUM | 6.5 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in WANotifier Notifier notifier allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2025-68019 | MEDIUM | 6.5 | 0.4% | Jan 22, 2026 | Missing Authorization vulnerability in cleverplugins SEO Booster seo-booster allows Exploiting Incorrectly Configured Ac... |
| CVE-2025-68018 | CRITICAL | 9.4 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in StackWC Order Listener for WooCommerce woc-order-alert allows Exploiting Incorrec... |
| CVE-2025-68017 | HIGH | 7.5 | 0.3% | Jan 22, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Antideo Antideo Em... |
| CVE-2025-68016 | MEDIUM | 6.5 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in Onepay Sri Lanka onepay Payment Gateway For WooCommerce onepay-payment-gateway-fo... |
| CVE-2025-68015 | CRITICAL | 9 | 0.3% | Jan 22, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner e... |
| CVE-2025-68013 | MEDIUM | 6.5 | 0.4% | Jan 22, 2026 | Missing Authorization vulnerability in cardpaysolutions Payment Gateway Authorize.Net CIM for WooCommerce authnet-cim-fo... |
| CVE-2025-68012 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dmytro Shteflyuk C... |
| CVE-2025-68011 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GLS GLS Shipping f... |
| CVE-2025-68010 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in netgsm Netgsm netg... |
| CVE-2025-68009 | MEDIUM | 6.5 | 0.4% | Jan 22, 2026 | Missing Authorization vulnerability in Codeless Slider Templates slider-templates allows Accessing Functionality Not Pro... |
| CVE-2025-68008 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mndpsingh287 WP Ma... |
| CVE-2025-68007 | MEDIUM | 6.5 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in Event Espresso Event Espresso 4 Decaf event-espresso-decaf allows Exploiting Inco... |
| CVE-2025-68006 | MEDIUM | 6.5 | 0.4% | Jan 22, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Deetronix Booking Ultra Pro booking-ultra-pro allows ... |
| CVE-2025-68004 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kapil Chugh My Pos... |
| CVE-2025-68003 | MEDIUM | 6.5 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in renatoatshown Shown Connector shown-connector allows Exploiting Incorrectly Confi... |
| CVE-2025-68001 | CRITICAL | 10 | 0.6% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in garidium g-FFL Checkout g-ffl-checkout allows Upload a ... |
| CVE-2025-67968 | CRITICAL | 9.9 | 0.5% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in InspiryThemes Real Homes CRM realhomes-crm allows Using... |
| CVE-2025-67967 | HIGH | 7.6 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in e-plugins Lawyer Directory lawyer-directory allows Exploiting Incorrectly Configu... |
| CVE-2025-67966 | HIGH | 8.8 | 0.4% | Jan 22, 2026 | Incorrect Privilege Assignment vulnerability in e-plugins Lawyer Directory lawyer-directory allows Privilege Escalation.... |
| CVE-2025-67964 | HIGH | 7.1 | 0.3% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Homey C... |
| CVE-2025-67963 | HIGH | 8.6 | 0.6% | Jan 22, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ovatheme Movie Booking m... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now