2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-67991HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vanquish User Extr...
CVE-2025-67990HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 GMap Ta...
CVE-2025-67988HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-67987HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech System...
CVE-2025-67984HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in calliko NPS comput...
CVE-2025-67982HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-67981HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-67980HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-67978HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FixBD Educare educ...
CVE-2025-67977HIGH8.2Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrect...
CVE-2025-67974HIGH7.5Missing Authorization vulnerability in WP Legal Pages WPLegalPages wplegalpages allows Exploiting Incorrectly Configured...
CVE-2025-67971HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPManageNinja Flue...
CVE-2025-60087HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-53237HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soflyy WP Wizard C...
CVE-2025-53233HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RylanH Storyform s...
CVE-2025-53231HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevstudio Easy T...
CVE-2025-53228HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jezza101 bbpress S...
CVE-2025-53217HIGH7.6Missing Authorization vulnerability in staviravn AIO WP Builder all-in-one-wp-builder allows Exploiting Incorrectly Conf...
CVE-2025-52744HIGH7.7Improper Control of Generation of Code ('Code Injection') vulnerability in inpersttion Inpersttion For Theme err-our-tea...
CVE-2025-8054HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText™ XM Fax allows ...
CVE-2025-9062HIGH7.3Authorization Bypass Through User-Controlled Key vulnerability in MeCODE Informatics and Engineering Services Ltd. Envan...
CVE-2025-15561HIGH7.8An attacker can exploit the update behavior of the WorkTime monitoring daemon to elevate privileges on the local system ...
CVE-2025-15560HIGH8.8An authenticated attacker with minimal permissions can exploit a SQL injection in the WorkTime server "widget" API endpo...
CVE-2025-13590HIGH7.2A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the d...
CVE-2025-12107HIGH7.2Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now