2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-69352MEDIUM5.4Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly C...
CVE-2025-69351HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ni...
CVE-2025-69350MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Accord...
CVE-2025-69349MEDIUM5.4Missing Authorization vulnerability in Fahad Mahmood RSS Feed Widget rss-feed-widget allows Exploiting Incorrectly Confi...
CVE-2025-69348MEDIUM4.3Missing Authorization vulnerability in CoolHappy The Events Calendar Countdown Addon countdown-for-the-events-calendar a...
CVE-2025-69346MEDIUM4.3Missing Authorization vulnerability in WPCenter AffiliateX affiliatex allows Exploiting Incorrectly Configured Access Co...
CVE-2025-69345MEDIUM4.3Missing Authorization vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Exploitin...
CVE-2025-69342HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69341MEDIUM5.4Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-ad...
CVE-2025-69336MEDIUM4.3Missing Authorization vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Exploiting...
CVE-2025-69335MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Team S...
CVE-2025-69334MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist...
CVE-2025-69331MEDIUM4.3Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configu...
CVE-2025-69327MEDIUM4.3Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectl...
CVE-2025-69086HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69085HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins JobBank ...
CVE-2025-69084HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Ga...
CVE-2025-69083HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-63083MEDIUM6.1Lack of output escaping leads to a XSS vector in the pagebreak plugin.
CVE-2025-63082MEDIUM6.1Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.
CVE-2025-60534CRITICAL9.8Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectiv...
CVE-2025-47553HIGH8.8Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This is...
CVE-2025-39477CRITICAL9.8Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control ...
CVE-2025-36589HIGH7.1Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vul...
CVE-2025-65212CRITICAL9.8An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the dev...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now