2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-68992MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xenioushk BWL Know...
CVE-2025-68991MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xenioushk BWL Pro ...
CVE-2025-68990HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in xenioushk BWL Pro ...
CVE-2025-68989MEDIUM4.3Insertion of Sensitive Information Into Sent Data vulnerability in Renzo Johnson contact-form-7-mailchimp-extension cont...
CVE-2025-68988MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in o2oe E-Invoice App Malaysia ...
CVE-2025-68987HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68985HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68984HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68983HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68982MEDIUM5.3Missing Authorization vulnerability in designthemes DesignThemes LMS Addon designthemes-lms-addon allows Exploiting Inco...
CVE-2025-68981MEDIUM5.3Missing Authorization vulnerability in designthemes HomeFix Elementor Portfolio homefix-ele-portfolio allows Exploiting ...
CVE-2025-68980MEDIUM5.3Missing Authorization vulnerability in designthemes WeDesignTech Portfolio wedesigntech-portfolio allows Exploiting Inco...
CVE-2025-68979MEDIUM5.3Authorization Bypass Through User-Controlled Key vulnerability in SimpleCalendar Google Calendar Events google-calendar-...
CVE-2025-68978MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Desig...
CVE-2025-68977MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Desig...
CVE-2025-68976MEDIUM5.4Missing Authorization vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploiting Incorrectly Configured...
CVE-2025-68975MEDIUM4.3Authorization Bypass Through User-Controlled Key vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploi...
CVE-2025-68974MEDIUM6.6Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-15245LOW3.3A vulnerability was found in D-Link DCS-850L 1.02.09. Affected is the function uploadfirmware of the component Firmware ...
CVE-2025-15244LOW3.7A vulnerability has been found in PHPEMS up to 11.0. This impacts an unknown function of the component Purchase Request ...
CVE-2025-15359CRITICAL9.8DVP-12SE11T - Out-of-bound memory write Vulnerability
CVE-2025-15243CRITICAL9.8A flaw has been found in code-projects Simple Stock System 1.0. This affects an unknown function of the file /market/log...
CVE-2025-15242LOW3.1A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function of the component Coupon H...
CVE-2025-15358HIGH7.5DVP-12SE11T - Denial of Service Vulnerability
CVE-2025-15241LOW3.5A security vulnerability has been detected in CloudPanel Community Edition up to 2.5.1. The affected element is an unkno...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now