2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69352 | MEDIUM | 5.4 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly C... |
| CVE-2025-69351 | HIGH | 8.5 | 0.2% | Jan 6, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ni... |
| CVE-2025-69350 | MEDIUM | 5.9 | 0.1% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Accord... |
| CVE-2025-69349 | MEDIUM | 5.4 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in Fahad Mahmood RSS Feed Widget rss-feed-widget allows Exploiting Incorrectly Confi... |
| CVE-2025-69348 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in CoolHappy The Events Calendar Countdown Addon countdown-for-the-events-calendar a... |
| CVE-2025-69346 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in WPCenter AffiliateX affiliatex allows Exploiting Incorrectly Configured Access Co... |
| CVE-2025-69345 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Exploitin... |
| CVE-2025-69342 | HIGH | 7.5 | 0.3% | Jan 6, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-69341 | MEDIUM | 5.4 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-ad... |
| CVE-2025-69336 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Exploiting... |
| CVE-2025-69335 | MEDIUM | 6.5 | 0.1% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Team S... |
| CVE-2025-69334 | MEDIUM | 6.5 | 0.1% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist... |
| CVE-2025-69331 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configu... |
| CVE-2025-69327 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectl... |
| CVE-2025-69086 | HIGH | 8.1 | 0.3% | Jan 6, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-69085 | HIGH | 7.1 | 0.2% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins JobBank ... |
| CVE-2025-69084 | HIGH | 7.1 | 0.2% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Ga... |
| CVE-2025-69083 | HIGH | 8.1 | 0.3% | Jan 6, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-63083 | MEDIUM | 6.1 | 0.2% | Jan 6, 2026 | Lack of output escaping leads to a XSS vector in the pagebreak plugin. |
| CVE-2025-63082 | MEDIUM | 6.1 | 0.2% | Jan 6, 2026 | Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags. |
| CVE-2025-60534 | CRITICAL | 9.8 | 0.7% | Jan 6, 2026 | Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectiv... |
| CVE-2025-47553 | HIGH | 8.8 | 0.3% | Jan 6, 2026 | Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This is... |
| CVE-2025-39477 | CRITICAL | 9.8 | 0.3% | Jan 6, 2026 | Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2025-36589 | HIGH | 7.1 | 0.2% | Jan 6, 2026 | Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vul... |
| CVE-2025-65212 | CRITICAL | 9.8 | 4.6% | Jan 6, 2026 | An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the dev... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now