2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-67519HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ni...
CVE-2025-67518HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Accor...
CVE-2025-67517HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in artplacer ArtPlace...
CVE-2025-67516HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store ...
CVE-2025-67515HIGH8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-67504CRITICAL9.8WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwo...
CVE-2025-67487HIGH8.6Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Versions 2.40.0 and be...
CVE-2025-67474MEDIUM4.3Missing Authorization vulnerability in Ultimate Member ForumWP forumwp allows Exploiting Incorrectly Configured Access C...
CVE-2025-67473MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in codeworkweb CWW Companion cww-companion allows Cross Site Request For...
CVE-2025-67472HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita mee...
CVE-2025-67471MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal Quick Contact Form quick-contact-form allows Cross Site Re...
CVE-2025-67470MEDIUM4.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Essential Plugin Portfolio a...
CVE-2025-67469MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in kubiq PDF Thumbnail Generator pdf-thumbnail-generator allows Cross Si...
CVE-2025-67468MEDIUM4.3Missing Authorization vulnerability in CRM Perks Integration for Salesforce and Contact Form 7, WPForms, Elementor, Form...
CVE-2025-67467MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in StellarWP GiveWP give allows Cross Site Request Forgery.This issue af...
CVE-2025-67466MEDIUM4.3Missing Authorization vulnerability in sergiotrinity Trinity Audio trinity-audio allows Exploiting Incorrectly Configure...
CVE-2025-67465MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud Simple Link Directory simple-link-directory allows Cross...
CVE-2025-66649Rejected reason: Further research determined the issue is not a vulnerability.
CVE-2025-66631CRITICAL9.8CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Ver...
CVE-2025-66627HIGH7.8Wasmi is a WebAssembly interpreter focused on constrained and embedded systems. In versions 0.41.0, 0.41.1, 0.42.0 throu...
CVE-2025-66622HIGH7.5matrix-sdk-base is the base component to build a Matrix client library. Versions 0.14.1 and prior are unable to handle r...
CVE-2025-66578HIGH7.5xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Versions 3.1.3 contain an authent...
CVE-2025-66568CRITICAL9.1The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vuln...
CVE-2025-66567CRITICAL9.1The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and includin...
CVE-2025-66565CRITICAL9.8Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now