2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68885 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in page-carbajal Custom Post Status custom-post-status allows Stored XSS... |
| CVE-2025-49354 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Mindstien Technologies Recent Posts From Each Category recent-posts-f... |
| CVE-2025-49353 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Marcin Kijak Noindex by Path noindex-by-path allows Stored XSS.This i... |
| CVE-2025-49345 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in mg12 WP-EasyArchives wp-easyarchives allows Stored XSS.This issue aff... |
| CVE-2025-49344 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in reneade SensitiveTagCloud sensitive-tag-cloud allows Stored XSS.This ... |
| CVE-2025-49343 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in socialprofilr Social Profilr social-profilr-display-social-network-pr... |
| CVE-2025-49342 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in merzedes Custom Style custom-style allows Stored XSS.This issue affec... |
| CVE-2025-13029 | HIGH | 7.5 | 0.2% | Dec 31, 2025 | The Knowband Mobile App Builder WordPress plugin before 3.0.0 does not have authorisation when deleting users via its RE... |
| CVE-2025-59137 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in eleopard Behance Portfolio Manager portfolio-manager-powered-by-behan... |
| CVE-2025-49346 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in peterwsterling Simple Archive Generator simple-archive-generator allo... |
| CVE-2025-15375 | HIGH | 8.8 | 0.4% | Dec 31, 2025 | A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of the file application/a... |
| CVE-2025-68131 | HIGH | 7.5 | 0.4% | Dec 31, 2025 | cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. Starting ... |
| CVE-2025-15371 | HIGH | 7.8 | 0.1% | Dec 31, 2025 | A vulnerability has been found in Tenda i24, 4G03 Pro, 4G05, 4G08, G0-8G-PoE, Nova MW5G and TEG5328F up to 65.10.15.6. A... |
| CVE-2025-62753 | HIGH | 7.5 | 0.3% | Dec 30, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-59131 | HIGH | 7.1 | 0.1% | Dec 30, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in hoernerfranz WP-CalDav2ICS wp-caldav2ics allows Stored XSS.This issue... |
| CVE-2025-15360 | HIGH | 7.2 | 0.3% | Dec 30, 2025 | A vulnerability was determined in newbee-mall-plus 2.0.0. This impacts the function Upload of the file src/main/java/ltd... |
| CVE-2025-66723 | HIGH | 7.5 | 0.4% | Dec 30, 2025 | inMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Librar... |
| CVE-2025-61594 | HIGH | 7.5 | 0.5% | Dec 30, 2025 | URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Rub... |
| CVE-2025-15356 | HIGH | 8.8 | 3.4% | Dec 30, 2025 | A vulnerability has been found in Tenda AC20 up to 16.03.08.12. The impacted element is the function sscanf of the file ... |
| CVE-2025-69261 | HIGH | 7.5 | 0.3% | Dec 30, 2025 | WasmEdge is a WebAssembly runtime. Prior to version 0.16.0-alpha.3, a multiplication in `WasmEdge/include/runtime/instan... |
| CVE-2025-69256 | HIGH | 7.5 | 1.9% | Dec 30, 2025 | The Serverless Framework is a framework for using AWS Lambda and other managed cloud services to build applications. Sta... |
| CVE-2025-66835 | HIGH | 7.1 | 0.2% | Dec 30, 2025 | TrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary... |
| CVE-2025-66834 | HIGH | 7.3 | 0.3% | Dec 30, 2025 | A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadshe... |
| CVE-2025-66824 | HIGH | 8.7 | 0.3% | Dec 30, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference fun... |
| CVE-2025-15264 | HIGH | 7.3 | 0.3% | Dec 30, 2025 | A vulnerability was determined in FeehiCMS up to 2.1.1. Impacted is an unknown function of the file frontend/web/timthum... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now