2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68995 | MEDIUM | 4.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in Premio My Sticky Elements mystickyelements allows Exploiting Incorrectly Configur... |
| CVE-2025-68994 | MEDIUM | 5.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in XforWooCommerce Product Loops for WooCommerce product-loops allows Exploiting Inc... |
| CVE-2025-68993 | MEDIUM | 5.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in XforWooCommerce Share, Print and PDF Products for WooCommerce share-print-pdf-woo... |
| CVE-2025-68992 | MEDIUM | 6.5 | 0.2% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xenioushk BWL Know... |
| CVE-2025-68991 | MEDIUM | 6.5 | 0.2% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xenioushk BWL Pro ... |
| CVE-2025-68990 | HIGH | 8.5 | 0.3% | Dec 30, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in xenioushk BWL Pro ... |
| CVE-2025-68989 | MEDIUM | 4.3 | 0.2% | Dec 30, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Renzo Johnson contact-form-7-mailchimp-extension cont... |
| CVE-2025-68988 | MEDIUM | 5.3 | 0.3% | Dec 30, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in o2oe E-Invoice App Malaysia ... |
| CVE-2025-68987 | HIGH | 7.5 | 0.4% | Dec 30, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68985 | HIGH | 7.5 | 0.4% | Dec 30, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68984 | HIGH | 7.5 | 0.4% | Dec 30, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68983 | HIGH | 7.5 | 0.4% | Dec 30, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68982 | MEDIUM | 5.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in designthemes DesignThemes LMS Addon designthemes-lms-addon allows Exploiting Inco... |
| CVE-2025-68981 | MEDIUM | 5.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in designthemes HomeFix Elementor Portfolio homefix-ele-portfolio allows Exploiting ... |
| CVE-2025-68980 | MEDIUM | 5.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in designthemes WeDesignTech Portfolio wedesigntech-portfolio allows Exploiting Inco... |
| CVE-2025-68979 | MEDIUM | 5.3 | 0.2% | Dec 30, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in SimpleCalendar Google Calendar Events google-calendar-... |
| CVE-2025-68978 | MEDIUM | 6.5 | 0.2% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Desig... |
| CVE-2025-68977 | MEDIUM | 6.5 | 0.2% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Desig... |
| CVE-2025-68976 | MEDIUM | 5.4 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploiting Incorrectly Configured... |
| CVE-2025-68975 | MEDIUM | 4.3 | 0.3% | Dec 30, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploi... |
| CVE-2025-68974 | MEDIUM | 6.6 | 0.4% | Dec 30, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-15245 | LOW | 3.3 | 0.5% | Dec 30, 2025 | A vulnerability was found in D-Link DCS-850L 1.02.09. Affected is the function uploadfirmware of the component Firmware ... |
| CVE-2025-15244 | LOW | 3.7 | 0.4% | Dec 30, 2025 | A vulnerability has been found in PHPEMS up to 11.0. This impacts an unknown function of the component Purchase Request ... |
| CVE-2025-15359 | CRITICAL | 9.8 | 0.3% | Dec 30, 2025 | DVP-12SE11T - Out-of-bound memory write Vulnerability |
| CVE-2025-15243 | CRITICAL | 9.8 | 0.4% | Dec 30, 2025 | A flaw has been found in code-projects Simple Stock System 1.0. This affects an unknown function of the file /market/log... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now