2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13183HIGH7.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hotech Soft...
CVE-2025-68561HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia Autom...
CVE-2025-68560HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68559MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem...
CVE-2025-68557MEDIUM4.3Missing Authorization vulnerability in Vikas Ratudi Chakra test chakra-test allows Exploiting Incorrectly Configured Acc...
CVE-2025-68556MEDIUM5.3Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrect...
CVE-2025-68551MEDIUM6.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vikas Ratudi VPSUForm v-form...
CVE-2025-68550HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme WPBulky...
CVE-2025-68548MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Res...
CVE-2025-68546HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68544HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-59886HIGH8.8Improper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker w...
CVE-2025-14635MEDIUM6.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_page_custom...
CVE-2025-14000MEDIUM6.4The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2025-14548MEDIUM6.4The Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'event_desc' parameter in all ver...
CVE-2025-14388CRITICAL9.8The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all ...
CVE-2025-14163MEDIUM4.3The Premium Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-14155MEDIUM5.3The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthor...
CVE-2025-12934HIGH8.1The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to unauthorized access and modification o...
CVE-2025-68655——Rejected reason: Not used
CVE-2025-68654——Rejected reason: Not used
CVE-2025-68653——Rejected reason: Not used
CVE-2025-68652——Rejected reason: Not used
CVE-2025-68651——Rejected reason: Not used
CVE-2025-68650——Rejected reason: Not used

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now