2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6326 | HIGH | 8.1 | 0.3% | Dec 18, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-6324 | HIGH | 7.1 | 0.1% | Dec 18, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MatrixAddons Easy ... |
| CVE-2025-67546 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs WP ERP erp allows Ret... |
| CVE-2025-66119 | HIGH | 7.1 | 0.1% | Dec 18, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel hostel ... |
| CVE-2025-66118 | HIGH | 7.1 | 0.1% | Dec 18, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Sprout Cl... |
| CVE-2025-66117 | HIGH | 7.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in Ays Pro Easy Form easy-form allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2025-66116 | HIGH | 7.5 | 0.2% | Dec 18, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in UserElements Ultimate Member Widgets for Elementor ul... |
| CVE-2025-66104 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in Anton Vanyukov Offload, AI & Optimize with Cloudflare Images cf-images allows Exp... |
| CVE-2025-66102 | HIGH | 7.1 | 0.1% | Dec 18, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision FV Ant... |
| CVE-2025-66100 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in Magnigenie RestroPress restropress allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-66088 | HIGH | 7.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in Property Hive PropertyHive propertyhive allows Exploiting Incorrectly Configured ... |
| CVE-2025-66078 | CRITICAL | 9.1 | 0.3% | Dec 18, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters Hotel Booking Lite motopress-hote... |
| CVE-2025-66074 | CRITICAL | 9 | 0.2% | Dec 18, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Path Traversa... |
| CVE-2025-66070 | HIGH | 7.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2025-66068 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured ... |
| CVE-2025-66054 | HIGH | 7.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access C... |
| CVE-2025-64378 | HIGH | 7.1 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in CridioStudio ListingPro listingpro allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-64377 | HIGH | 8.1 | 0.3% | Dec 18, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-64376 | HIGH | 7.1 | 0.1% | Dec 18, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio Listi... |
| CVE-2025-64375 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in Mahmudul Hasan Arif WP Social Ninja wp-social-reviews allows Exploiting Incorrect... |
| CVE-2025-64374 | CRITICAL | 9.9 | 0.4% | Dec 18, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in StylemixThemes Motors motors allows Using Malicious Fil... |
| CVE-2025-64373 | HIGH | 8.1 | 0.3% | Dec 18, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-64372 | HIGH | 7.1 | 0.1% | Dec 18, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shinetheme Travele... |
| CVE-2025-64371 | HIGH | 8.5 | 0.3% | Dec 18, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Travele... |
| CVE-2025-64295 | MEDIUM | 6.5 | 0.3% | Dec 18, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi All In One SEO Pack all-in-one-seo-pack a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now