2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60127 | MEDIUM | 5.4 | 0.3% | Sep 26, 2025 | Missing Authorization vulnerability in ArtistScope CopySafe Web Protection wp-copysafe-web allows Exploiting Incorrectly... |
| CVE-2025-60126 | HIGH | 8.8 | 0.4% | Sep 26, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-60125 | MEDIUM | 5.3 | 0.3% | Sep 26, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in themelooks FoodBook foodbook allows Retrieve Embedded... |
| CVE-2025-60124 | MEDIUM | 6.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Hellyer Simpl... |
| CVE-2025-60123 | MEDIUM | 4.3 | 0.2% | Sep 26, 2025 | Missing Authorization vulnerability in HivePress HivePress Claim Listings hivepress-claim-listings allows Exploiting Inc... |
| CVE-2025-60122 | MEDIUM | 4.3 | 0.2% | Sep 26, 2025 | Missing Authorization vulnerability in HivePress HivePress Claim Listings hivepress-claim-listings allows Exploiting Inc... |
| CVE-2025-60121 | MEDIUM | 5.3 | 0.3% | Sep 26, 2025 | Missing Authorization vulnerability in Ex-Themes WooEvents woo-events allows Exploiting Incorrectly Configured Access Co... |
| CVE-2025-60120 | MEDIUM | 5.3 | 0.3% | Sep 26, 2025 | Missing Authorization vulnerability in WPDirectoryKit WP Directory Kit wpdirectorykit allows Exploiting Incorrectly Conf... |
| CVE-2025-60119 | MEDIUM | 5.3 | 0.3% | Sep 26, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in CoSchedule CoSchedule cosche... |
| CVE-2025-60118 | HIGH | 8.5 | 0.3% | Sep 26, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Potenzaglobalsolut... |
| CVE-2025-60117 | MEDIUM | 4.3 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in TangibleWP Vehica Core vehica-core allows Cross Site Request Forgery.... |
| CVE-2025-60116 | HIGH | 8.8 | 0.3% | Sep 26, 2025 | Missing Authorization vulnerability in ThemeGoods Grand Conference Theme Custom Post Type grandconference-custom-post al... |
| CVE-2025-60115 | MEDIUM | 4.3 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in instapagedev Instapage Plugin instapage allows Cross Site Request For... |
| CVE-2025-60114 | MEDIUM | 6.6 | 0.3% | Sep 26, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in YayCommerce YayCurrency yaycurrency allows Co... |
| CVE-2025-60113 | MEDIUM | 4.3 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in grooni Groovy Menu groovy-menu-free allows Cross Site Request Forgery... |
| CVE-2025-60112 | MEDIUM | 6.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi aTheme... |
| CVE-2025-60111 | HIGH | 8.8 | 0.2% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in javothemes Javo Core javo-core allows Authentication Bypass.This issu... |
| CVE-2025-60110 | HIGH | 8.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup AllIn... |
| CVE-2025-60109 | HIGH | 8.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Lambe... |
| CVE-2025-60108 | HIGH | 8.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Lambe... |
| CVE-2025-60107 | HIGH | 8.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Lambe... |
| CVE-2025-60106 | MEDIUM | 4.9 | 0.3% | Sep 26, 2025 | Missing Authorization vulnerability in Roxnor EmailKit emailkit allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2025-60105 | MEDIUM | 6.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in metaphorcreations ... |
| CVE-2025-60104 | MEDIUM | 5.9 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Gallery... |
| CVE-2025-60103 | MEDIUM | 5.4 | 0.2% | Sep 26, 2025 | Missing Authorization vulnerability in CridioStudio ListingPro listingpro-plugin allows Exploiting Incorrectly Configure... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now