2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67710 | MEDIUM | 6.1 | 0.2% | Dec 31, 2025 | There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co... |
| CVE-2025-67709 | MEDIUM | 6.1 | 0.2% | Dec 31, 2025 | There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co... |
| CVE-2025-67708 | MEDIUM | 6.1 | 0.2% | Dec 31, 2025 | There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co... |
| CVE-2025-67707 | MEDIUM | 5.6 | 0.2% | Dec 31, 2025 | ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a rem... |
| CVE-2025-67706 | MEDIUM | 5.6 | 0.3% | Dec 31, 2025 | ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a rem... |
| CVE-2025-67705 | MEDIUM | 6.1 | 0.2% | Dec 31, 2025 | There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co... |
| CVE-2025-67704 | MEDIUM | 6.1 | 0.2% | Dec 31, 2025 | There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co... |
| CVE-2025-67703 | MEDIUM | 6.1 | 0.2% | Dec 31, 2025 | There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co... |
| CVE-2025-66148 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Conformer for Elementor conformer-elementor allows Exploiting Incorrect... |
| CVE-2025-66146 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Logger for Elementor logger-elementor allows Exploiting Incorrectly Con... |
| CVE-2025-66145 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Worker for WPBakery worker-wpbakery allows Exploiting Incorrectly Confi... |
| CVE-2025-66144 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Worker for Elementor worker-elementor allows Exploiting Incorrectly Con... |
| CVE-2025-28973 | MEDIUM | 6.5 | 0.3% | Dec 31, 2025 | Path Traversal: '.../...//' vulnerability in AA-Team Pro Bulk Watermark Plugin for WordPress pro-watermark allows Path T... |
| CVE-2025-66153 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Headinger for Elementor headinger-elementor allows Exploiting Incorrect... |
| CVE-2025-66152 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Criptopayer for Elementor criptopayer-elementor allows Exploiting Incor... |
| CVE-2025-66151 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Countdowner for Elementor countdowner-elementor allows Exploiting Incor... |
| CVE-2025-66150 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Appender appender allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2025-66149 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove UnGrabber ungrabber allows Exploiting Incorrectly Configured Access Con... |
| CVE-2025-34467 | MEDIUM | 4.3 | 0.2% | Dec 31, 2025 | ZwiiCMS versions prior to 13.7.00 contain a denial-of-service vulnerability in multiple administrative endpoints due to ... |
| CVE-2025-62989 | MEDIUM | 5.9 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gora Tech Cooked c... |
| CVE-2025-59135 | MEDIUM | 5.9 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eleopard Behance P... |
| CVE-2025-49355 | MEDIUM | 5.9 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ikaes Accessibilit... |
| CVE-2025-49337 | MEDIUM | 5.9 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in janhenckens Dashbo... |
| CVE-2025-66160 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Select Graphist for Elementor Graphist for Elementor graphist-elemento... |
| CVE-2025-66159 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Walker for Elementor walker-elementor allows Exploiting Incorrectly Con... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now