2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13183 | HIGH | 7.3 | 0.2% | Dec 23, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hotech Soft... |
| CVE-2025-68561 | HIGH | 7.6 | 0.2% | Dec 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia Autom... |
| CVE-2025-68560 | HIGH | 7.5 | 0.3% | Dec 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68559 | MEDIUM | 6.5 | 0.1% | Dec 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem... |
| CVE-2025-68557 | MEDIUM | 4.3 | 0.2% | Dec 23, 2025 | Missing Authorization vulnerability in Vikas Ratudi Chakra test chakra-test allows Exploiting Incorrectly Configured Acc... |
| CVE-2025-68556 | MEDIUM | 5.3 | 0.2% | Dec 23, 2025 | Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrect... |
| CVE-2025-68551 | MEDIUM | 6.5 | 0.2% | Dec 23, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vikas Ratudi VPSUForm v-form... |
| CVE-2025-68550 | HIGH | 7.6 | 0.2% | Dec 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme WPBulky... |
| CVE-2025-68548 | MEDIUM | 6.5 | 0.1% | Dec 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Res... |
| CVE-2025-68546 | HIGH | 7.5 | 0.3% | Dec 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68544 | HIGH | 7.5 | 0.3% | Dec 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-59886 | HIGH | 8.8 | 0.3% | Dec 23, 2025 | Improper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker w... |
| CVE-2025-14635 | MEDIUM | 6.4 | 0.3% | Dec 23, 2025 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_page_custom... |
| CVE-2025-14000 | MEDIUM | 6.4 | 0.2% | Dec 23, 2025 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2025-14548 | MEDIUM | 6.4 | 0.2% | Dec 23, 2025 | The Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'event_desc' parameter in all ver... |
| CVE-2025-14388 | CRITICAL | 9.8 | 0.4% | Dec 23, 2025 | The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all ... |
| CVE-2025-14163 | MEDIUM | 4.3 | 0.1% | Dec 23, 2025 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2025-14155 | MEDIUM | 5.3 | 0.7% | Dec 23, 2025 | The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthor... |
| CVE-2025-12934 | HIGH | 8.1 | 0.4% | Dec 23, 2025 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to unauthorized access and modification o... |
| CVE-2025-68655 | — | — | — | Dec 23, 2025 | Rejected reason: Not used |
| CVE-2025-68654 | — | — | — | Dec 23, 2025 | Rejected reason: Not used |
| CVE-2025-68653 | — | — | — | Dec 23, 2025 | Rejected reason: Not used |
| CVE-2025-68652 | — | — | — | Dec 23, 2025 | Rejected reason: Not used |
| CVE-2025-68651 | — | — | — | Dec 23, 2025 | Rejected reason: Not used |
| CVE-2025-68650 | — | — | — | Dec 23, 2025 | Rejected reason: Not used |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now