2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68586 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Gora Tech Cooked cooked allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2025-68585 | LOW | 2.7 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Ben Balter WP Document Revisions wp-document-revisions allows Exploiting Incorrec... |
| CVE-2025-68584 | MEDIUM | 4.3 | 0.1% | Dec 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Constantin Boiangiu Vimeotheque codeflavors-vimeo-video-post-lite all... |
| CVE-2025-68583 | MEDIUM | 4.3 | 0.1% | Dec 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Tikweb Management Fast User Switching fast-user-switching allows Cros... |
| CVE-2025-68582 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Funnelforms Funnelforms Free funnelforms-free allows Exploiting Incorrectly Confi... |
| CVE-2025-68581 | MEDIUM | 5.4 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in YITHEMES YITH Slider for page builders yith-slider-for-page-builders allows Explo... |
| CVE-2025-68580 | MEDIUM | 4.3 | 0.1% | Dec 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in pluginsware Advanced Classifieds & Directory Pro advanced-classifieds... |
| CVE-2025-68579 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in FolioVision FV Simpler SEO fv-all-in-one-seo-pack allows Exploiting Incorrectly C... |
| CVE-2025-68578 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Addonify Addonify addonify-quick-view allows Exploiting Incorrectly Configured Ac... |
| CVE-2025-68577 | MEDIUM | 4.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Virusdie Virusdie virusdie allows Exploiting Incorrectly Configured Access Contro... |
| CVE-2025-68576 | MEDIUM | 4.3 | 0.2% | Dec 24, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Virusdie Virusdie virusdie a... |
| CVE-2025-68575 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Wappointment team Wappointment wappointment allows Exploiting Incorrectly Configu... |
| CVE-2025-68574 | MEDIUM | 5.9 | 0.2% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidcoders WPBaker... |
| CVE-2025-68573 | MEDIUM | 5.4 | 0.1% | Dec 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Simple Keyword to Link simple-keyword-to-link allow... |
| CVE-2025-68572 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Spider Themes BBP Core bbp-core allows Exploiting Incorrectly Configured Access C... |
| CVE-2025-68571 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in SALESmanago SALESmanago & Leadoo salesmanago allows Exploiting Incorrectly Config... |
| CVE-2025-68570 | HIGH | 7.6 | 0.3% | Dec 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Cap... |
| CVE-2025-68569 | MEDIUM | 6.5 | 0.3% | Dec 24, 2025 | Missing Authorization vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allows Exploitin... |
| CVE-2025-68568 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Claspo Popup Builders Claspo – Popups, Spin the Wheel & Email Capture claspo allo... |
| CVE-2025-68567 | MEDIUM | 5.4 | 0.1% | Dec 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows C... |
| CVE-2025-68566 | MEDIUM | 5.9 | 0.2% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auction... |
| CVE-2025-68565 | MEDIUM | 5.3 | 0.3% | Dec 24, 2025 | Missing Authorization vulnerability in JayBee Twitch Player ttv-easy-embed-player allows Exploiting Incorrectly Configur... |
| CVE-2025-68563 | HIGH | 7.5 | 0.3% | Dec 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68540 | HIGH | 7.5 | 0.4% | Dec 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68537 | HIGH | 7.5 | 0.3% | Dec 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now