2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63044 | MEDIUM | 6.5 | 0.2% | Dec 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xpro Xpro Elemento... |
| CVE-2025-63042 | MEDIUM | 6.5 | 0.2% | Dec 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS ... |
| CVE-2025-63037 | MEDIUM | 6.5 | 0.2% | Dec 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DFDevelopment Ronn... |
| CVE-2025-63036 | HIGH | 7.5 | 0.4% | Dec 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-63035 | MEDIUM | 6.5 | 0.2% | Dec 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VibeThemes WPLMS w... |
| CVE-2025-63034 | MEDIUM | 5.4 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in Steve Truman Page View Count page-views-count allows Exploiting Incorrectly Confi... |
| CVE-2025-63033 | MEDIUM | 5.9 | 0.2% | Dec 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Riyadh Ahmed Make ... |
| CVE-2025-63030 | HIGH | 7.1 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal New User Approve new-user-approve allows Cross Site Reques... |
| CVE-2025-63028 | MEDIUM | 5.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2025-63025 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in Xagio SEO Xagio SEO xagio-seo allows Exploiting Incorrectly Configured Access Con... |
| CVE-2025-63024 | MEDIUM | 5.4 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in tychesoftwares Order Delivery Date for WooCommerce order-delivery-date-for-woocom... |
| CVE-2025-63023 | MEDIUM | 5.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in Easy Payment Payment Gateway for PayPal on WooCommerce woo-paypal-gateway allows ... |
| CVE-2025-63015 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in paysera WooCommerce Payment Gateway - Paysera woo-payment-gateway-paysera allows ... |
| CVE-2025-63013 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThimPress WP Hotel Booking w... |
| CVE-2025-63012 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Cross Site Request... |
| CVE-2025-63011 | MEDIUM | 5.9 | 0.2% | Dec 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Hotel... |
| CVE-2025-63010 | MEDIUM | 4.9 | 0.1% | Dec 9, 2025 | Server-Side Request Forgery (SSRF) vulnerability in ThemesInflow Hercules Core hercules-core allows Server Side Request... |
| CVE-2025-63009 | MEDIUM | 5.3 | 0.2% | Dec 9, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in yuvalo WP Google Analytics E... |
| CVE-2025-63008 | MEDIUM | 5.3 | 0.3% | Dec 9, 2025 | Missing Authorization vulnerability in weDevs WP ERP erp allows Exploiting Incorrectly Configured Access Control Securit... |
| CVE-2025-63007 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Metagauss EventPrime eventprime-event-calendar-manage... |
| CVE-2025-63006 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incor... |
| CVE-2025-63003 | HIGH | 7.5 | 0.4% | Dec 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-62999 | MEDIUM | 5.4 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in themezaa Litho Addons litho-addons allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-62997 | MEDIUM | 5.3 | 0.2% | Dec 9, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in levelfourdevelopment WP EasyCart wp-easycart allows R... |
| CVE-2025-62996 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in Code Amp Custom Layouts – Post + Product grids made easy custom-layouts allows Ex... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now