2025 CVE Vulnerabilities

45,208 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62868HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-9978MEDIUM6.8The Jeg Kit for Elementor WordPress plugin before 2.7.0 does not sanitize SVG file contents when uploaded via xmlrpc.ph...
CVE-2025-9158MEDIUM5.3The Request Tracker software is vulnerable to a Stored XSS vulnerability in calendar invitation parsing feature, which d...
CVE-2025-61931MEDIUM5.4Pleasanter contains a stored cross-site scripting vulnerability in Body, Description and Comments, which allows an attac...
CVE-2025-58070MEDIUM6.1Pleasanter contains a stored cross-site scripting vulnerability in Preview for Attachments, which allows an attacker to ...
CVE-2025-10874MEDIUM5.5The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.2...
CVE-2025-10723LOW2.7The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate pa...
CVE-2025-62835Rejected reason: Not used
CVE-2025-62834Rejected reason: Not used
CVE-2025-62833Rejected reason: Not used
CVE-2025-62832Rejected reason: Not used
CVE-2025-62831Rejected reason: Not used
CVE-2025-62830Rejected reason: Not used
CVE-2025-62829Rejected reason: Not used
CVE-2025-62828Rejected reason: Not used
CVE-2025-62827Rejected reason: Not used
CVE-2025-7730MEDIUM6.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘percentage’ parameter i...
CVE-2025-62254HIGH7.5The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 th...
CVE-2025-60023MEDIUM6.3A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerabilit...
CVE-2025-59776MEDIUM6.3A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerabilit...
CVE-2025-58429HIGH8.3A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerabilit...
CVE-2025-62688HIGH7.1An incorrect permission assignment for a critical resource vulnerability was discovered in Productivity Suite software v...
CVE-2025-62498HIGH8.8A relative path traversal (ZipSlip) vulnerability was discovered in Productivity Suite software version 4.4.1.19. The ...
CVE-2025-61977HIGH7.3A weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software ve...
CVE-2025-61934CRITICAL10A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. T...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now