2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62041 | HIGH | 7.1 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem... |
| CVE-2025-62040 | HIGH | 7.1 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YOP YOP Poll yop-p... |
| CVE-2025-62039 | HIGH | 7.5 | 1.2% | Nov 6, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Ays Pro AI ChatBot with ChatGPT and Content Generator... |
| CVE-2025-62038 | MEDIUM | 6.5 | 0.3% | Nov 6, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Sovlix MeetingHub meetinghub allows Retrieve Embedded... |
| CVE-2025-62037 | MEDIUM | 6.5 | 0.3% | Nov 6, 2025 | Missing Authorization vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4. |
| CVE-2025-62036 | HIGH | 7.1 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Togo togo.Th... |
| CVE-2025-62035 | HIGH | 8.8 | 0.4% | Nov 6, 2025 | Deserialization of Untrusted Data vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4. |
| CVE-2025-62034 | HIGH | 8.8 | 0.3% | Nov 6, 2025 | Incorrect Privilege Assignment vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4. |
| CVE-2025-62033 | MEDIUM | 6.5 | 0.2% | Nov 6, 2025 | Missing Authorization vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4. |
| CVE-2025-62032 | MEDIUM | 6.5 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Clou... |
| CVE-2025-62031 | HIGH | 7.1 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Comp... |
| CVE-2025-62030 | MEDIUM | 6.5 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Comp... |
| CVE-2025-62028 | MEDIUM | 4.3 | 0.2% | Nov 6, 2025 | Missing Authorization vulnerability in ThemeNectar Salient salient.This issue affects Salient: from n/a through < 17.4.0... |
| CVE-2025-62018 | MEDIUM | 5.3 | 0.2% | Nov 6, 2025 | Missing Authorization vulnerability in hogash KALLYAS kallyas.This issue affects KALLYAS: from n/a through <= 4.22.0. |
| CVE-2025-62017 | MEDIUM | 5.4 | 0.2% | Nov 6, 2025 | Missing Authorization vulnerability in hogash KALLYAS kallyas.This issue affects KALLYAS: from n/a through <= 4.22.0. |
| CVE-2025-62016 | CRITICAL | 9.9 | 0.3% | Nov 6, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in hogash KALLYAS kallyas.This issue affects KALLYAS: from... |
| CVE-2025-62014 | HIGH | 8.1 | 0.4% | Nov 6, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-62012 | MEDIUM | 6.5 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem... |
| CVE-2025-62011 | MEDIUM | 6.5 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem... |
| CVE-2025-62010 | HIGH | 8.1 | 0.4% | Nov 6, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-60248 | HIGH | 7.5 | 0.4% | Nov 6, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-60247 | MEDIUM | 6.5 | 0.3% | Nov 6, 2025 | Missing Authorization vulnerability in Bux Bux Woocommerce bux-woocommerce allows Accessing Functionality Not Properly C... |
| CVE-2025-60245 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | Deserialization of Untrusted Data vulnerability in WP User Manager WP User Manager wp-user-manager allows Object Injecti... |
| CVE-2025-60244 | HIGH | 7.1 | 0.2% | Nov 6, 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in RealMag777 TableOn posts-... |
| CVE-2025-60243 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | Incorrect Privilege Assignment vulnerability in Holest Engineering Selling Commander for WooCommerce selling-commander-c... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now