2025 CVE Vulnerabilities
45,143 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68051 | HIGH | 7.5 | 0.3% | Feb 20, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Shiprocket Shiprocket shiprocket allows Exploiting Inc... |
| CVE-2025-68050 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Missing Authorization vulnerability in Leadpages Leadpages leadpages allows Exploiting Incorrectly Configured Access Con... |
| CVE-2025-68048 | HIGH | 7.5 | 0.3% | Feb 20, 2026 | Missing Authorization vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextmove-lite allows Exploiting Incorr... |
| CVE-2025-68043 | HIGH | 7.3 | 0.6% | Feb 20, 2026 | Missing Authorization vulnerability in LottieFiles LottieFiles lottiefiles allows Exploiting Incorrectly Configured Acce... |
| CVE-2025-68042 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Missing Authorization vulnerability in Travelpayouts Travelpayouts travelpayouts allows Exploiting Incorrectly Configure... |
| CVE-2025-68037 | HIGH | 7.1 | 0.3% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atlas Gondal Expor... |
| CVE-2025-68032 | MEDIUM | 6.5 | 0.3% | Feb 20, 2026 | Missing Authorization vulnerability in Passionate Brains Advanced WC Analytics advance-wc-analytics allows Exploiting In... |
| CVE-2025-68031 | HIGH | 7.1 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in faraz sms افزونه پ... |
| CVE-2025-68028 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Missing Authorization vulnerability in Passionate Brains GA4WP: Google Analytics for WordPress ga-for-wp allows Exploiti... |
| CVE-2025-68026 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Missing Authorization vulnerability in Niaj Morshed LC Wizard ghl-wizard allows Exploiting Incorrectly Configured Access... |
| CVE-2025-68025 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Missing Authorization vulnerability in Addonify Addonify Floating Cart For WooCommerce addonify-floating-cart allows Exp... |
| CVE-2025-68024 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Missing Authorization vulnerability in Addonify Addonify – WooCommerce Wishlist addonify-wishlist allows Exploiting Inco... |
| CVE-2025-68023 | MEDIUM | 6.5 | 0.3% | Feb 20, 2026 | Missing Authorization vulnerability in Addonify Addonify – Compare Products For WooCommerce addonify-compare-products al... |
| CVE-2025-68022 | HIGH | 7.3 | 0.3% | Feb 20, 2026 | Missing Authorization vulnerability in soporteblue Plugin BlueX for WooCommerce bluex-for-woocommerce allows Exploiting ... |
| CVE-2025-68021 | MEDIUM | 6.5 | 0.3% | Feb 20, 2026 | Missing Authorization vulnerability in ConveyThis ConveyThis conveythis-translate allows Exploiting Incorrectly Configur... |
| CVE-2025-68005 | MEDIUM | 6.5 | 0.3% | Feb 20, 2026 | Missing Authorization vulnerability in themewant Easy Hotel Booking easy-hotel allows Exploiting Incorrectly Configured ... |
| CVE-2025-68002 | MEDIUM | 6.5 | 0.3% | Feb 20, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 100plugins Open User Map... |
| CVE-2025-68000 | MEDIUM | 6.5 | 0.3% | Feb 20, 2026 | Missing Authorization vulnerability in PickPlugins Testimonial Slider testimonial allows Exploiting Incorrectly Configur... |
| CVE-2025-67998 | HIGH | 8.8 | 0.4% | Feb 20, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in kamleshyadav Miraculous Elementor miraculous-e... |
| CVE-2025-67997 | CRITICAL | 9.8 | 0.4% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in BoldThemes Travelicious travelicious allows Object Injection.This iss... |
| CVE-2025-67996 | CRITICAL | 9.8 | 0.4% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in BoldThemes Nestin nestin allows Object Injection.This issue affects N... |
| CVE-2025-67995 | CRITICAL | 9.8 | 0.5% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in LoftOcean PatioTime patiotime allows Object Injection.This issue affe... |
| CVE-2025-67994 | HIGH | 7.5 | 0.3% | Feb 20, 2026 | Missing Authorization vulnerability in YayCommerce YayCurrency yaycurrency allows Exploiting Incorrectly Configured Acce... |
| CVE-2025-67993 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Missing Authorization vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Exploiting Incorrectly Confi... |
| CVE-2025-67992 | HIGH | 8.1 | 0.5% | Feb 20, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now