2025 CVE Vulnerabilities
45,143 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69378 | HIGH | 7.2 | 0.4% | Feb 20, 2026 | Incorrect Privilege Assignment vulnerability in XforWooCommerce Product Filter for WooCommerce prdctfltr allows Privileg... |
| CVE-2025-69377 | HIGH | 7.7 | 0.5% | Feb 20, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fiel... |
| CVE-2025-69376 | HIGH | 8.6 | 0.5% | Feb 20, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fiel... |
| CVE-2025-69375 | HIGH | 8.1 | 0.5% | Feb 20, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-69374 | HIGH | 8.1 | 0.5% | Feb 20, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-69373 | HIGH | 7.5 | 0.4% | Feb 20, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-69372 | CRITICAL | 9.8 | 0.4% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in AncoraThemes SevenHills sevenhills allows Object Injection.This issue... |
| CVE-2025-69371 | CRITICAL | 9.8 | 0.4% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in AncoraThemes KindlyCare kindlycare allows Object Injection.This issue... |
| CVE-2025-69370 | CRITICAL | 9.8 | 0.4% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in ThemeGoods Capella capella allows Object Injection.This issue affects... |
| CVE-2025-69368 | HIGH | 7.1 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GT3themes SOHO - P... |
| CVE-2025-69367 | HIGH | 7.1 | 0.3% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GT3themes Oyster -... |
| CVE-2025-69366 | CRITICAL | 9.3 | 0.4% | Feb 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Emerc... |
| CVE-2025-69365 | CRITICAL | 9.3 | 0.3% | Feb 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Uroan... |
| CVE-2025-69337 | CRITICAL | 9.3 | 0.3% | Feb 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in don-themes Wolmart... |
| CVE-2025-69330 | HIGH | 7.1 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jthemes Prestige p... |
| CVE-2025-69329 | CRITICAL | 9.8 | 0.4% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in Jthemes Prestige prestige allows Object Injection.This issue affects ... |
| CVE-2025-69328 | HIGH | 8.8 | 0.3% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-... |
| CVE-2025-69326 | HIGH | 7.1 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms ne... |
| CVE-2025-69325 | MEDIUM | 5.3 | 0.4% | Feb 20, 2026 | Path Traversal: '.../...//' vulnerability in primersoftware Primer MyData for Woocommerce primer-mydata allows Path Trav... |
| CVE-2025-69324 | HIGH | 7.1 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms ne... |
| CVE-2025-69323 | HIGH | 7.1 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs Slimsta... |
| CVE-2025-69322 | HIGH | 8.1 | 0.5% | Feb 20, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-69310 | CRITICAL | 9.3 | 0.3% | Feb 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Woodl... |
| CVE-2025-69309 | CRITICAL | 9.3 | 0.3% | Feb 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Saasp... |
| CVE-2025-69308 | CRITICAL | 9.3 | 0.3% | Feb 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Nestb... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now