2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67519 | HIGH | 7.6 | 0.4% | Dec 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ni... |
| CVE-2025-67518 | HIGH | 8.5 | 0.3% | Dec 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Accor... |
| CVE-2025-67517 | HIGH | 8.5 | 0.3% | Dec 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in artplacer ArtPlace... |
| CVE-2025-67516 | HIGH | 8.5 | 0.3% | Dec 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store ... |
| CVE-2025-67515 | HIGH | 8.8 | 0.4% | Dec 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-67504 | CRITICAL | 9.8 | 0.4% | Dec 9, 2025 | WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwo... |
| CVE-2025-67487 | HIGH | 8.6 | 0.3% | Dec 9, 2025 | Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Versions 2.40.0 and be... |
| CVE-2025-67474 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in Ultimate Member ForumWP forumwp allows Exploiting Incorrectly Configured Access C... |
| CVE-2025-67473 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in codeworkweb CWW Companion cww-companion allows Cross Site Request For... |
| CVE-2025-67472 | HIGH | 8.8 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita mee... |
| CVE-2025-67471 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal Quick Contact Form quick-contact-form allows Cross Site Re... |
| CVE-2025-67470 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Essential Plugin Portfolio a... |
| CVE-2025-67469 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in kubiq PDF Thumbnail Generator pdf-thumbnail-generator allows Cross Si... |
| CVE-2025-67468 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in CRM Perks Integration for Salesforce and Contact Form 7, WPForms, Elementor, Form... |
| CVE-2025-67467 | MEDIUM | 5.4 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in StellarWP GiveWP give allows Cross Site Request Forgery.This issue af... |
| CVE-2025-67466 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in sergiotrinity Trinity Audio trinity-audio allows Exploiting Incorrectly Configure... |
| CVE-2025-67465 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud Simple Link Directory simple-link-directory allows Cross... |
| CVE-2025-66649 | — | — | — | Dec 9, 2025 | Rejected reason: Further research determined the issue is not a vulnerability. |
| CVE-2025-66631 | CRITICAL | 9.8 | 0.6% | Dec 9, 2025 | CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Ver... |
| CVE-2025-66627 | HIGH | 7.8 | 0.1% | Dec 9, 2025 | Wasmi is a WebAssembly interpreter focused on constrained and embedded systems. In versions 0.41.0, 0.41.1, 0.42.0 throu... |
| CVE-2025-66622 | HIGH | 7.5 | 0.3% | Dec 9, 2025 | matrix-sdk-base is the base component to build a Matrix client library. Versions 0.14.1 and prior are unable to handle r... |
| CVE-2025-66578 | HIGH | 7.5 | 0.2% | Dec 9, 2025 | xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Versions 3.1.3 contain an authent... |
| CVE-2025-66568 | CRITICAL | 9.1 | 0.2% | Dec 9, 2025 | The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vuln... |
| CVE-2025-66567 | CRITICAL | 9.1 | 0.4% | Dec 9, 2025 | The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and includin... |
| CVE-2025-66565 | CRITICAL | 9.8 | 0.4% | Dec 9, 2025 | Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's c... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now