2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68873 | HIGH | 7.1 | 0.1% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chloédigital PRIME... |
| CVE-2025-68867 | MEDIUM | 6.5 | 0.2% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in anibalwainstein Ef... |
| CVE-2025-67937 | HIGH | 8.1 | 0.4% | Jan 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-67936 | HIGH | 8.1 | 0.4% | Jan 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-67935 | HIGH | 8.1 | 0.4% | Jan 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-67934 | HIGH | 8.1 | 0.4% | Jan 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-67933 | HIGH | 7.1 | 0.1% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in taskbuilder Taskbu... |
| CVE-2025-67932 | HIGH | 7.1 | 0.1% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes Listeo ... |
| CVE-2025-67931 | HIGH | 7.5 | 0.2% | Jan 8, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in AITpro BulletProof Security bulletproof-security allo... |
| CVE-2025-67930 | HIGH | 7.1 | 0.2% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vernon Systems Lim... |
| CVE-2025-67928 | CRITICAL | 9.3 | 0.3% | Jan 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themesuite Automot... |
| CVE-2025-67927 | HIGH | 7.1 | 0.2% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spencer Haws Link ... |
| CVE-2025-67926 | MEDIUM | 6.5 | 0.3% | Jan 8, 2026 | Missing Authorization vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Exploiting Incorrectly Confi... |
| CVE-2025-67925 | HIGH | 7.5 | 0.5% | Jan 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-67924 | CRITICAL | 9.9 | 0.3% | Jan 8, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Corpkit corpkit allows Upload a Web Shell to... |
| CVE-2025-67922 | HIGH | 7.1 | 0.2% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand R... |
| CVE-2025-67921 | HIGH | 8.5 | 0.3% | Jan 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VanKarWai Lobo lob... |
| CVE-2025-67920 | HIGH | 8.1 | 0.4% | Jan 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-67919 | MEDIUM | 6.5 | 0.3% | Jan 8, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in WofficeIO Woffice Core woffice-core allows Exploiting ... |
| CVE-2025-67918 | HIGH | 7.1 | 0.2% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice ... |
| CVE-2025-67917 | MEDIUM | 6.5 | 0.2% | Jan 8, 2026 | Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2025-67916 | HIGH | 7.1 | 0.2% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify Jobify ... |
| CVE-2025-67915 | HIGH | 8.8 | 0.4% | Jan 8, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Arraytics Timetics timetics allows Authenticat... |
| CVE-2025-67914 | HIGH | 7.7 | 0.3% | Jan 8, 2026 | Path Traversal: '.../...//' vulnerability in beeteam368 VidMov vidmov allows Path Traversal.This issue affects VidMov: f... |
| CVE-2025-67913 | MEDIUM | 6.5 | 0.2% | Jan 8, 2026 | Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Accessing Functionali... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now