2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62746 | MEDIUM | 6.5 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeFlavors Featur... |
| CVE-2025-61557 | HIGH | 7.5 | 0.6% | Dec 30, 2025 | nixseparatedebuginfod before v0.4.1 is vulnerable to Directory Traversal. |
| CVE-2025-15255 | CRITICAL | 9.8 | 3.9% | Dec 30, 2025 | A vulnerability was determined in Tenda W6-S 1.0.0.4(510). This impacts an unknown function of the file /bin/httpd of th... |
| CVE-2025-15254 | HIGH | 8.8 | 3.3% | Dec 30, 2025 | A vulnerability was found in Tenda W6-S 1.0.0.4(510). This affects the function TendaAte of the file /goform/ate of the ... |
| CVE-2025-15253 | HIGH | 8.8 | 0.6% | Dec 30, 2025 | A vulnerability has been found in Tenda M3 1.0.0.13(4903). The impacted element is an unknown function of the file /gofo... |
| CVE-2025-15252 | HIGH | 8.8 | 2.9% | Dec 30, 2025 | A flaw has been found in Tenda M3 1.0.0.13(4903). The affected element is the function formSetRemoteDhcpForAp of the fil... |
| CVE-2025-15251 | MEDIUM | 6.3 | 0.3% | Dec 30, 2025 | A vulnerability was detected in beecue FastBee up to 2.1. Impacted is the function getRootElement of the file springboot... |
| CVE-2025-15250 | MEDIUM | 4.7 | 0.2% | Dec 30, 2025 | A security vulnerability has been detected in 08CMS Novel System up to 3.4. This issue affects some unknown processing o... |
| CVE-2025-15249 | MEDIUM | 5.1 | 0.2% | Dec 30, 2025 | A weakness has been identified in zhujunliang3 work_platform up to 6bc5a50bb527ce27f7906d11ea6ec139beb79c31. This vulner... |
| CVE-2025-15248 | LOW | 3.5 | 0.2% | Dec 30, 2025 | A security flaw has been discovered in sunhailin12315 product-review 商品评价系统 up to 91ead6890b4065bb45b7602d0d73348e75cb46... |
| CVE-2025-14426 | MEDIUM | 4.3 | 0.2% | Dec 30, 2025 | The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil... |
| CVE-2025-15247 | CRITICAL | 9.8 | 0.4% | Dec 30, 2025 | A vulnerability was identified in gmg137 snap7-rs up to 153d3e8c16decd7271e2a5b2e3da4d6f68589424. Affected by this issue... |
| CVE-2025-15246 | MEDIUM | 6.3 | 0.2% | Dec 30, 2025 | A vulnerability was determined in aizuda snail-job up to 1.7.0 on macOS. Affected by this vulnerability is the function ... |
| CVE-2025-14509 | HIGH | 7.2 | 0.5% | Dec 30, 2025 | The Lucky Wheel for WooCommerce – Spin a Sale plugin for WordPress is vulnerable to PHP Code Injection in all versions u... |
| CVE-2025-69093 | MEDIUM | 5.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in wpdesk ShopMagic shopmagic-for-woocommerce allows Exploiting Incorrectly Configur... |
| CVE-2025-69092 | MEDIUM | 6.5 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essent... |
| CVE-2025-69091 | MEDIUM | 4.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in Kraft Plugins Demo Importer Plus demo-importer-plus allows Exploiting Incorrectly... |
| CVE-2025-69089 | MEDIUM | 6.5 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in autolistings Auto ... |
| CVE-2025-69088 | MEDIUM | 6.5 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vidish Combo Offer... |
| CVE-2025-69034 | HIGH | 8.1 | 0.3% | Dec 30, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-69033 | MEDIUM | 6.5 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Blog Fil... |
| CVE-2025-69032 | MEDIUM | 5.4 | 0.2% | Dec 30, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes FiveStar fivestar allows Exploiting Inco... |
| CVE-2025-69031 | MEDIUM | 5.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in Skywarrior Arcane arcane allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2025-69030 | MEDIUM | 5.4 | 0.2% | Dec 30, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Backpack Traveler backpacktraveler allow... |
| CVE-2025-69029 | MEDIUM | 5.4 | 0.2% | Dec 30, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Select-Themes Struktur struktur allows Exploiting Inco... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now