2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23719 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zckevin ZhinaTwitt... |
| CVE-2025-23707 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matamko En Masse e... |
| CVE-2025-23705 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terry Zielke Zielk... |
| CVE-2025-23667 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Christopher Church... |
| CVE-2025-66153 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Headinger for Elementor headinger-elementor allows Exploiting Incorrect... |
| CVE-2025-66152 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Criptopayer for Elementor criptopayer-elementor allows Exploiting Incor... |
| CVE-2025-66151 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Countdowner for Elementor countdowner-elementor allows Exploiting Incor... |
| CVE-2025-66150 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Appender appender allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2025-66149 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove UnGrabber ungrabber allows Exploiting Incorrectly Configured Access Con... |
| CVE-2025-34468 | CRITICAL | 9.8 | 0.6% | Dec 31, 2025 | libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a stack-based buffer overflow in address re... |
| CVE-2025-34467 | MEDIUM | 4.3 | 0.2% | Dec 31, 2025 | ZwiiCMS versions prior to 13.7.00 contain a denial-of-service vulnerability in multiple administrative endpoints due to ... |
| CVE-2025-15394 | HIGH | 7.2 | 0.4% | Dec 31, 2025 | A vulnerability was detected in iCMS up to 8.0.0. Affected is the function Save of the file app/config/ConfigAdmincp.php... |
| CVE-2025-15393 | HIGH | 8.8 | 0.4% | Dec 31, 2025 | A security vulnerability has been detected in Kohana KodiCMS up to 13.82.135. This impacts the function Save of the file... |
| CVE-2025-62989 | MEDIUM | 5.9 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gora Tech Cooked c... |
| CVE-2025-59135 | MEDIUM | 5.9 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eleopard Behance P... |
| CVE-2025-49355 | MEDIUM | 5.9 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ikaes Accessibilit... |
| CVE-2025-49337 | MEDIUM | 5.9 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in janhenckens Dashbo... |
| CVE-2025-23608 | HIGH | 7.1 | 0.2% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Omar Mohamed Moham... |
| CVE-2025-15392 | HIGH | 8.8 | 0.2% | Dec 31, 2025 | A weakness has been identified in Kohana KodiCMS up to 13.82.135. This affects the function like of the file cms/modules... |
| CVE-2025-15391 | CRITICAL | 9.8 | 3.7% | Dec 31, 2025 | A weakness has been identified in D-Link DIR-806A 100CNb11. Affected is the function ssdpcgi_main of the component SSDP ... |
| CVE-2025-66160 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Select Graphist for Elementor Graphist for Elementor graphist-elemento... |
| CVE-2025-66159 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Walker for Elementor walker-elementor allows Exploiting Incorrectly Con... |
| CVE-2025-66158 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Gmaper for Elementor gmaper-elementor allows Exploiting Incorrectly Con... |
| CVE-2025-66157 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Sliper for Elementor sliper-elementor allows Exploiting Incorrectly Con... |
| CVE-2025-66156 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Watcher for Elementor watcher-elementor allows Exploiting Incorrectly C... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now