2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67617 | CRITICAL | 9.8 | 0.5% | Jan 22, 2026 | Deserialization of Untrusted Data vulnerability in themeton Consult Aid consultaid allows Object Injection.This issue af... |
| CVE-2025-67616 | HIGH | 8.1 | 0.5% | Jan 22, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-67615 | HIGH | 8.1 | 0.5% | Jan 22, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-67614 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree Th... |
| CVE-2025-67221 | HIGH | 7.5 | 0.5% | Jan 22, 2026 | The orjson.dumps function in orjson thru 3.11.4 does not limit recursion for deeply nested JSON documents. |
| CVE-2025-66143 | MEDIUM | 5.4 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in merkulove Crumber crumber-elementor allows Exploiting Incorrectly Configured Acce... |
| CVE-2025-66142 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in merkulove Comparimager for Elementor comparimager-elementor allows Exploiting Inc... |
| CVE-2025-66141 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in merkulove Scroller scroller allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2025-66140 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in merkulove Uper for Elementor uper-elementor allows Exploiting Incorrectly Configu... |
| CVE-2025-66139 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in merkulove Audier For Elementor audier-elementor allows Exploiting Incorrectly Con... |
| CVE-2025-66138 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in merkulove Motionger for Elementor motionger-elementor allows Exploiting Incorrect... |
| CVE-2025-66137 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in merkulove Searcher for Elementor searcher-elementor allows Exploiting Incorrectly... |
| CVE-2025-66136 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in merkulove Carter for Elementor carter-elementor allows Exploiting Incorrectly Con... |
| CVE-2025-66135 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in merkulove Imager for Elementor imager-elementor allows Exploiting Incorrectly Con... |
| CVE-2025-64252 | MEDIUM | 4.9 | 0.2% | Jan 22, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Marco Milesi ANAC XML Viewer anac-xml-viewer allows Server Side Requ... |
| CVE-2025-63051 | MEDIUM | 4.3 | 0.3% | Jan 22, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in sizam REHub Framework rehub-... |
| CVE-2025-63026 | MEDIUM | 6.5 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand R... |
| CVE-2025-63019 | MEDIUM | 5.3 | 0.4% | Jan 22, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Johan Jonk Stenström Cookies and Content Security Pol... |
| CVE-2025-63018 | MEDIUM | 4.3 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in wproyal Bard bard allows Exploiting Incorrectly Configured Access Control Securit... |
| CVE-2025-63017 | HIGH | 7.5 | 0.5% | Jan 22, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-62754 | MEDIUM | 5.3 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in Kapil Paul Payment Gateway bKash for WC woo-payment-bkash allows Exploiting Incor... |
| CVE-2025-62741 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Pool Services pool-services allows Server Side Request... |
| CVE-2025-62106 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in Mario Peshev WP-CRM System wp-crm-system allows Exploiting Incorrectly Configured... |
| CVE-2025-62077 | MEDIUM | 5.9 | 0.3% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SEOSEON EUROPE S.L... |
| CVE-2025-62056 | CRITICAL | 9.9 | 0.5% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes News Event news-event.This issue affects Ne... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now