2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68087 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Modalier for Elementor modalier-elementor allows Exploiting Incorrectly... |
| CVE-2025-68086 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Reformer for Elementor reformer-elementor allows Exploiting Incorrectly... |
| CVE-2025-68085 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Buttoner for Elementor buttoner-elementor allows Exploiting Incorrectly... |
| CVE-2025-68084 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in Nitesh Ultimate Auction ultimate-auction allows Exploiting Incorrectly Configure... |
| CVE-2025-68083 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Meks Meks Quick Plugin Disabler meks-quick-plugin-disabler allows Cro... |
| CVE-2025-68082 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in SEMrush CY LTD Semrush Content Toolkit semrush-contentshake allows Cr... |
| CVE-2025-68080 | MEDIUM | 6.5 | 0.1% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal User Av... |
| CVE-2025-68079 | MEDIUM | 6.5 | 0.1% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNectar Salien... |
| CVE-2025-68078 | MEDIUM | 6.5 | 0.1% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNectar Salien... |
| CVE-2025-68077 | MEDIUM | 6.5 | 0.1% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Select-Themes Stoc... |
| CVE-2025-68076 | MEDIUM | 6.5 | 0.1% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Select-Themes Stoc... |
| CVE-2025-68071 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in g5theme Essential Real Estate essential-real-estate al... |
| CVE-2025-68070 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vektor,Inc. VK Goo... |
| CVE-2025-68068 | HIGH | 7.5 | 0.3% | Dec 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68067 | HIGH | 7.5 | 0.3% | Dec 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68066 | HIGH | 7.5 | 0.3% | Dec 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68065 | HIGH | 7.5 | 0.3% | Dec 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68062 | HIGH | 7.5 | 0.4% | Dec 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68061 | HIGH | 7.5 | 0.3% | Dec 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68056 | HIGH | 8.5 | 0.2% | Dec 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LBG Z... |
| CVE-2025-68055 | HIGH | 8.5 | 0.3% | Dec 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Boo... |
| CVE-2025-68054 | HIGH | 8.5 | 0.2% | Dec 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Count... |
| CVE-2025-68053 | HIGH | 8.5 | 0.2% | Dec 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup xProm... |
| CVE-2025-67999 | HIGH | 7.6 | 0.4% | Dec 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stefano Lissa News... |
| CVE-2025-67989 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Server-Side Request Forgery (SSRF) vulnerability in LMPixels Kerge kerge allows Server Side Request Forgery.This issue a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now