2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67991 | HIGH | 7.1 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vanquish User Extr... |
| CVE-2025-67990 | HIGH | 7.1 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 GMap Ta... |
| CVE-2025-67988 | HIGH | 8.1 | 0.5% | Feb 20, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-67987 | HIGH | 8.5 | 0.3% | Feb 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech System... |
| CVE-2025-67984 | HIGH | 7.1 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in calliko NPS comput... |
| CVE-2025-67982 | HIGH | 8.1 | 0.6% | Feb 20, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-67981 | HIGH | 8.1 | 0.6% | Feb 20, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-67980 | HIGH | 8.1 | 0.5% | Feb 20, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-67978 | HIGH | 7.1 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FixBD Educare educ... |
| CVE-2025-67977 | HIGH | 8.2 | 0.3% | Feb 20, 2026 | Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrect... |
| CVE-2025-67974 | HIGH | 7.5 | 0.3% | Feb 20, 2026 | Missing Authorization vulnerability in WP Legal Pages WPLegalPages wplegalpages allows Exploiting Incorrectly Configured... |
| CVE-2025-67971 | HIGH | 7.1 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPManageNinja Flue... |
| CVE-2025-60087 | HIGH | 8.1 | 0.6% | Feb 20, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-53237 | HIGH | 7.1 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soflyy WP Wizard C... |
| CVE-2025-53233 | HIGH | 7.1 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RylanH Storyform s... |
| CVE-2025-53231 | HIGH | 7.1 | 0.3% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevstudio Easy T... |
| CVE-2025-53228 | HIGH | 7.1 | 0.3% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jezza101 bbpress S... |
| CVE-2025-53217 | HIGH | 7.6 | 0.2% | Feb 20, 2026 | Missing Authorization vulnerability in staviravn AIO WP Builder all-in-one-wp-builder allows Exploiting Incorrectly Conf... |
| CVE-2025-52744 | HIGH | 7.7 | 0.3% | Feb 20, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in inpersttion Inpersttion For Theme err-our-tea... |
| CVE-2025-8054 | HIGH | 7.5 | 0.3% | Feb 19, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText™ XM Fax allows ... |
| CVE-2025-9062 | HIGH | 7.3 | 0.2% | Feb 19, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in MeCODE Informatics and Engineering Services Ltd. Envan... |
| CVE-2025-15561 | HIGH | 7.8 | 0.1% | Feb 19, 2026 | An attacker can exploit the update behavior of the WorkTime monitoring daemon to elevate privileges on the local system ... |
| CVE-2025-15560 | HIGH | 8.8 | 0.3% | Feb 19, 2026 | An authenticated attacker with minimal permissions can exploit a SQL injection in the WorkTime server "widget" API endpo... |
| CVE-2025-13590 | HIGH | 7.2 | 0.7% | Feb 19, 2026 | A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the d... |
| CVE-2025-12107 | HIGH | 7.2 | 0.6% | Feb 19, 2026 | Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now