2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-67911CRITICAL9.8Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injecti...
CVE-2025-67910CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload...
CVE-2025-27004HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Famou...
CVE-2025-27002HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Count...
CVE-2025-23993CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RiceTheme Felan Fr...
CVE-2025-23504CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in RiceTheme Felan Framework felan-framework allo...
CVE-2025-22728HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech Workrea...
CVE-2025-22726MEDIUM6.4Server-Side Request Forgery (SSRF) vulnerability in _nK nK Themes Helper nk-themes-helper allows Server Side Request For...
CVE-2025-22725HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in loopus WP Virtual ...
CVE-2025-22715HIGH7.5Missing Authorization vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_Attract...
CVE-2025-22713HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vanquish WooCommer...
CVE-2025-22712HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-22708HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-22707HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-22509HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-15224LOW3.1When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly s...
CVE-2025-15079MEDIUM5.3When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenl...
CVE-2025-14984MEDIUM6.4The Gutenverse Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all version...
CVE-2025-14819MEDIUM5.3When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option...
CVE-2025-14524MEDIUM5.3When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a s...
CVE-2025-14431HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-14430HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-14429HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-14360HIGH7.5Missing Authorization vulnerability in Kaira Blockons blockons allows Accessing Functionality Not Properly Constrained b...
CVE-2025-14359HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now