2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66534 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in Elated-Themes The Aisle theaisle allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-66533 | MEDIUM | 5.3 | 0.2% | Dec 9, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in StellarWP GiveWP give allows Code Injection.T... |
| CVE-2025-66532 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in Mikado-Themes Powerlift powerlift allows Exploiting Incorrectly Configured Access... |
| CVE-2025-66531 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Cross... |
| CVE-2025-66530 | MEDIUM | 4.3 | 0.3% | Dec 9, 2025 | Missing Authorization vulnerability in Webba Appointment Booking Webba Booking webba-booking-lite allows Exploiting Inco... |
| CVE-2025-66529 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Chartify chart-builder allows Cross Site Request Forgery.This... |
| CVE-2025-66528 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customize... |
| CVE-2025-66527 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in VanKarWai Lobo lobo allows Exploiting Incorrectly Configured Access Control Secur... |
| CVE-2025-66526 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in Essekia Tablesome tablesome allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2025-66525 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in Elastic Email Elastic Email Sender elastic-email-sender allows Exploiting Incorre... |
| CVE-2025-66508 | MEDIUM | 6.5 | 0.2% | Dec 9, 2025 | 1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.14 and below use Gin's defau... |
| CVE-2025-66507 | HIGH | 7.5 | 0.4% | Dec 9, 2025 | 1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.13 and below allow an unauth... |
| CVE-2025-66271 | HIGH | 8.4 | 0.1% | Dec 9, 2025 | Clone for Windows provided by ELECOM CO.,LTD. registers a Windows service with an unquoted file path. A user with the wr... |
| CVE-2025-65287 | MEDIUM | 4.3 | 0.7% | Dec 9, 2025 | An unauthenticated directory traversal vulnerability in cgi-bin/upload.cgi in SNMP Web Pro 1.1 allows a remote attacker ... |
| CVE-2025-64696 | MEDIUM | 4.8 | 0.1% | Dec 9, 2025 | Android App "Brother iPrint&Scan" versions 6.13.7 and earlier improperly uses an external cache directory. If exploited,... |
| CVE-2025-64257 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in Joe Dolson My Tickets my-tickets allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-64256 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Folio simple-folio allows Cross Site Request Forge... |
| CVE-2025-64255 | LOW | 2.7 | 0.3% | Dec 9, 2025 | Missing Authorization vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Exploiting ... |
| CVE-2025-64254 | LOW | 2.7 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in Ronald Huereca Photo Block photo-block allows Exploiting Incorrectly Configured A... |
| CVE-2025-63077 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Exploiting ... |
| CVE-2025-63076 | HIGH | 7.5 | 0.4% | Dec 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-63075 | MEDIUM | 6.5 | 0.2% | Dec 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in muffingroup Bethem... |
| CVE-2025-63074 | HIGH | 7.5 | 0.4% | Dec 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-63073 | MEDIUM | 6.5 | 0.2% | Dec 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dream-Theme The7 d... |
| CVE-2025-63072 | MEDIUM | 6.5 | 0.2% | Dec 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in THEMECO Cornerston... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now