2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62761 | MEDIUM | 6.5 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BasePress Knowledg... |
| CVE-2025-62760 | MEDIUM | 6.5 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev BuddyPres... |
| CVE-2025-62759 | MEDIUM | 6.5 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Ser... |
| CVE-2025-62758 | MEDIUM | 6.5 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Funnelforms Funnel... |
| CVE-2025-62146 | MEDIUM | 6.5 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maksym Marko MX Ti... |
| CVE-2025-62137 | MEDIUM | 6.5 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shuttlethemes Shut... |
| CVE-2025-62136 | MEDIUM | 6.5 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thinkupthemes Melo... |
| CVE-2025-14783 | MEDIUM | 4.3 | 0.3% | Dec 31, 2025 | The Easy Digital Downloads plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and includi... |
| CVE-2025-69277 | MEDIUM | 4.5 | 0.2% | Dec 31, 2025 | libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_e... |
| CVE-2025-14434 | MEDIUM | 5.3 | 0.2% | Dec 31, 2025 | The Ultimate Post Kit Addons for Elementor WordPress plugin before 4.0.16 exposes multiple AJAX “load more” endpoints su... |
| CVE-2025-15374 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | A vulnerability was detected in EyouCMS up to 1.7.7. The affected element is an unknown function of the file application... |
| CVE-2025-15373 | MEDIUM | 4.3 | 0.2% | Dec 31, 2025 | A security vulnerability has been detected in EyouCMS up to 1.7.7. Impacted is the function saveRemote of the file appli... |
| CVE-2025-15372 | MEDIUM | 4.8 | 0.2% | Dec 31, 2025 | A weakness has been identified in youlaitech vue3-element-admin up to 3.4.0. This issue affects some unknown processing ... |
| CVE-2025-15223 | MEDIUM | 6.1 | 0.3% | Dec 31, 2025 | A vulnerability was found in Philipinho Simple-PHP-Blog up to 94b5d3e57308bce5dfbc44c3edafa9811893d958. Impacted is an u... |
| CVE-2025-15112 | MEDIUM | 5.4 | 0.2% | Dec 30, 2025 | Ksenia Security lares (legacy model) version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that... |
| CVE-2025-14987 | MEDIUM | 5.3 | 0.4% | Dec 30, 2025 | When system.enableCrossNamespaceCommands is enabled (on by default), the Temporal server permits certain workflow task c... |
| CVE-2025-69257 | MEDIUM | 6.7 | 0.1% | Dec 30, 2025 | theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to versi... |
| CVE-2025-69210 | MEDIUM | 5.4 | 1.0% | Dec 30, 2025 | FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.7, a stored cr... |
| CVE-2025-66823 | MEDIUM | 5.4 | 0.2% | Dec 30, 2025 | An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to... |
| CVE-2025-15258 | MEDIUM | 6.1 | 0.2% | Dec 30, 2025 | A weakness has been identified in Edimax BR-6208AC 1.02/1.03. Affected by this issue is the function formALGSetup of the... |
| CVE-2025-68950 | MEDIUM | 6.2 | 0.2% | Dec 30, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12... |
| CVE-2025-66103 | MEDIUM | 6.5 | 0.2% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revmakx WPCal.io w... |
| CVE-2025-66094 | MEDIUM | 6.5 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dmccan Yada Wiki y... |
| CVE-2025-65925 | MEDIUM | 6.5 | 0.2% | Dec 30, 2025 | An issue was discovered in Zeroheight (SaaS) prior to 2025-06-13. A legacy user creation API pathway allowed accounts to... |
| CVE-2025-62128 | MEDIUM | 4.3 | 0.3% | Dec 30, 2025 | Missing Authorization vulnerability in SiteLock SiteLock Security – WP Hardening, Login Security & Malware Scans siteloc... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now