2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-60127MEDIUM5.4Missing Authorization vulnerability in ArtistScope CopySafe Web Protection wp-copysafe-web allows Exploiting Incorrectly...
CVE-2025-60126HIGH8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-60125MEDIUM5.3Insertion of Sensitive Information Into Sent Data vulnerability in themelooks FoodBook foodbook allows Retrieve Embedded...
CVE-2025-60124MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Hellyer Simpl...
CVE-2025-60123MEDIUM4.3Missing Authorization vulnerability in HivePress HivePress Claim Listings hivepress-claim-listings allows Exploiting Inc...
CVE-2025-60122MEDIUM4.3Missing Authorization vulnerability in HivePress HivePress Claim Listings hivepress-claim-listings allows Exploiting Inc...
CVE-2025-60121MEDIUM5.3Missing Authorization vulnerability in Ex-Themes WooEvents woo-events allows Exploiting Incorrectly Configured Access Co...
CVE-2025-60120MEDIUM5.3Missing Authorization vulnerability in WPDirectoryKit WP Directory Kit wpdirectorykit allows Exploiting Incorrectly Conf...
CVE-2025-60119MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in CoSchedule CoSchedule cosche...
CVE-2025-60118HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Potenzaglobalsolut...
CVE-2025-60117MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in TangibleWP Vehica Core vehica-core allows Cross Site Request Forgery....
CVE-2025-60116HIGH8.8Missing Authorization vulnerability in ThemeGoods Grand Conference Theme Custom Post Type grandconference-custom-post al...
CVE-2025-60115MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in instapagedev Instapage Plugin instapage allows Cross Site Request For...
CVE-2025-60114MEDIUM6.6Improper Control of Generation of Code ('Code Injection') vulnerability in YayCommerce YayCurrency yaycurrency allows Co...
CVE-2025-60113MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in grooni Groovy Menu groovy-menu-free allows Cross Site Request Forgery...
CVE-2025-60112MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi aTheme...
CVE-2025-60111HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in javothemes Javo Core javo-core allows Authentication Bypass.This issu...
CVE-2025-60110HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup AllIn...
CVE-2025-60109HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Lambe...
CVE-2025-60108HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Lambe...
CVE-2025-60107HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Lambe...
CVE-2025-60106MEDIUM4.9Missing Authorization vulnerability in Roxnor EmailKit emailkit allows Exploiting Incorrectly Configured Access Control ...
CVE-2025-60105MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in metaphorcreations ...
CVE-2025-60104MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Gallery...
CVE-2025-60103MEDIUM5.4Missing Authorization vulnerability in CridioStudio ListingPro listingpro-plugin allows Exploiting Incorrectly Configure...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now