2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67911 | CRITICAL | 9.8 | 0.4% | Jan 8, 2026 | Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injecti... |
| CVE-2025-67910 | CRITICAL | 9.1 | 0.3% | Jan 8, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload... |
| CVE-2025-27004 | HIGH | 7.1 | 0.2% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Famou... |
| CVE-2025-27002 | HIGH | 7.1 | 0.2% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Count... |
| CVE-2025-23993 | CRITICAL | 9.3 | 0.4% | Jan 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RiceTheme Felan Fr... |
| CVE-2025-23504 | CRITICAL | 9.8 | 0.4% | Jan 8, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in RiceTheme Felan Framework felan-framework allo... |
| CVE-2025-22728 | HIGH | 8.5 | 0.3% | Jan 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech Workrea... |
| CVE-2025-22726 | MEDIUM | 6.4 | 0.2% | Jan 8, 2026 | Server-Side Request Forgery (SSRF) vulnerability in _nK nK Themes Helper nk-themes-helper allows Server Side Request For... |
| CVE-2025-22725 | HIGH | 7.1 | 0.2% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in loopus WP Virtual ... |
| CVE-2025-22715 | HIGH | 7.5 | 0.4% | Jan 8, 2026 | Missing Authorization vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_Attract... |
| CVE-2025-22713 | HIGH | 8.5 | 0.3% | Jan 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vanquish WooCommer... |
| CVE-2025-22712 | HIGH | 8.1 | 0.5% | Jan 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-22708 | HIGH | 8.1 | 0.5% | Jan 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-22707 | HIGH | 8.1 | 0.5% | Jan 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-22509 | HIGH | 8.1 | 0.5% | Jan 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-15224 | LOW | 3.1 | 0.4% | Jan 8, 2026 | When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly s... |
| CVE-2025-15079 | MEDIUM | 5.3 | 0.5% | Jan 8, 2026 | When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenl... |
| CVE-2025-14984 | MEDIUM | 6.4 | 0.3% | Jan 8, 2026 | The Gutenverse Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all version... |
| CVE-2025-14819 | MEDIUM | 5.3 | 0.7% | Jan 8, 2026 | When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option... |
| CVE-2025-14524 | MEDIUM | 5.3 | 0.6% | Jan 8, 2026 | When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a s... |
| CVE-2025-14431 | HIGH | 8.1 | 0.4% | Jan 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-14430 | HIGH | 8.1 | 0.4% | Jan 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-14429 | HIGH | 8.1 | 0.4% | Jan 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-14360 | HIGH | 7.5 | 0.3% | Jan 8, 2026 | Missing Authorization vulnerability in Kaira Blockons blockons allows Accessing Functionality Not Properly Constrained b... |
| CVE-2025-14359 | HIGH | 8.1 | 0.4% | Jan 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now