2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67961 | MEDIUM | 6.4 | 0.2% | Jan 22, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Marco van Wieren WPO365 wpo365-login allows Server Side Request Forg... |
| CVE-2025-67960 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes WorkSco... |
| CVE-2025-67959 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes WorkSco... |
| CVE-2025-67958 | MEDIUM | 6.5 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in Taxcloud TaxCloud for WooCommerce simple-sales-tax allows Exploiting Incorrectly ... |
| CVE-2025-67957 | HIGH | 8.1 | 0.5% | Jan 22, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-67956 | HIGH | 8.2 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Confi... |
| CVE-2025-67955 | HIGH | 7.5 | 0.5% | Jan 22, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-67954 | MEDIUM | 6.5 | 0.4% | Jan 22, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Dimitri Grassi Salon booking... |
| CVE-2025-67953 | HIGH | 8.1 | 0.3% | Jan 22, 2026 | Incorrect Privilege Assignment vulnerability in Booking Activities Team Booking Activities booking-activities allows Pri... |
| CVE-2025-67952 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand T... |
| CVE-2025-67949 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designingmedia Hos... |
| CVE-2025-67947 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scriptsbundle AdFo... |
| CVE-2025-67946 | HIGH | 8.1 | 0.5% | Jan 22, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-67945 | CRITICAL | 9.3 | 0.4% | Jan 22, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MailerLite MailerL... |
| CVE-2025-67944 | CRITICAL | 9.1 | 0.5% | Jan 22, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-test... |
| CVE-2025-67943 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auction... |
| CVE-2025-67942 | MEDIUM | 6.5 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in peachpayments Peach Payments Gateway wc-peach-payments-gateway allows Exploiting ... |
| CVE-2025-67941 | HIGH | 8.1 | 0.5% | Jan 22, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-67940 | HIGH | 8.1 | 0.5% | Jan 22, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-67939 | MEDIUM | 6.5 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in Tickera Tickera tickera-event-ticketing-system allows Exploiting Incorrectly Conf... |
| CVE-2025-67938 | HIGH | 8.1 | 0.6% | Jan 22, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-67923 | HIGH | 7.1 | 0.3% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngi... |
| CVE-2025-67626 | MEDIUM | 4.3 | 0.1% | Jan 22, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Angel Costa WP SEO Search wp-seo-search allows Cross Site Request For... |
| CVE-2025-67620 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CleverSoft Anon an... |
| CVE-2025-67619 | HIGH | 8.8 | 0.5% | Jan 22, 2026 | Deserialization of Untrusted Data vulnerability in designthemes Kids Heaven kids-world allows Object Injection.This issu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now