2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-64273MEDIUM6.5Missing Authorization vulnerability in GetResponse Email marketing for WordPress by GetResponse Official getresponse-off...
CVE-2025-64272MEDIUM6.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in GetResponse Email marketing ...
CVE-2025-64270MEDIUM6.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in masteriyo Masteriyo - LMS le...
CVE-2025-64268HIGH7.5Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Contr...
CVE-2025-64266HIGH8.8Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-...
CVE-2025-64260HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Milesi ANAC ...
CVE-2025-64258HIGH7.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in wpweb Follow My Blog Post fo...
CVE-2025-64233CRITICAL9.8Deserialization of Untrusted Data vulnerability in BoldThemes Codiqa codiqa allows Object Injection.This issue affects C...
CVE-2025-64231CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google S...
CVE-2025-64230HIGH7.7Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Chill Filr filr-prote...
CVE-2025-64227CRITICAL9.8Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows O...
CVE-2025-64225MEDIUM6.5Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in colabrio Stockie Extra st...
CVE-2025-64223HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-64222HIGH7.5Missing Authorization vulnerability in FantasticPlugins WooCommerce Recover Abandoned Cart rac allows Exploiting Incorre...
CVE-2025-64221HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Reser...
CVE-2025-64218HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in WP Chill Passster content-protector allows Retrieve E...
CVE-2025-64217HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Photogr...
CVE-2025-64214HIGH7.5Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro...
CVE-2025-64213HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-le...
CVE-2025-64209HIGH7.5Missing Authorization vulnerability in StylemixThemes Masterstudy masterstudy allows Accessing Functionality Not Properl...
CVE-2025-64207HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TieLabs Jannah jan...
CVE-2025-64206CRITICAL9.8Deserialization of Untrusted Data vulnerability in TieLabs Jannah jannah allows Object Injection.This issue affects Jann...
CVE-2025-64205HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-64203HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress Mailster...
CVE-2025-64193HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now