2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69025 | MEDIUM | 4.3 | 0.2% | Dec 30, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Aethonic Poptics poptics all... |
| CVE-2025-69024 | MEDIUM | 6.5 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in bizswoop BizPrint print-google-cloud-print-gcp-woocommerce allows Exploiting Inco... |
| CVE-2025-69023 | MEDIUM | 4.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in Marketing Fire Discussion Board wp-discussion-board allows Exploiting Incorrectly... |
| CVE-2025-69022 | MEDIUM | 5.4 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in Weblizar - WordPress Themes & Plugin HR Management Lite hr-management-lite allows... |
| CVE-2025-69021 | MEDIUM | 5.4 | 0.1% | Dec 30, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Popup box ays-popup-box allows Cross Site Request Forgery.Thi... |
| CVE-2025-69020 | MEDIUM | 6.5 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software... |
| CVE-2025-69019 | MEDIUM | 6.5 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FlippingBook Flipp... |
| CVE-2025-69018 | MEDIUM | 6.5 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shamalli Web Direc... |
| CVE-2025-69017 | MEDIUM | 6.5 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magnigenie RestroP... |
| CVE-2025-69016 | MEDIUM | 4.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Exploi... |
| CVE-2025-69014 | MEDIUM | 4.9 | 0.1% | Dec 30, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Youzify Youzify youzify allows Server Side Request Forgery.This issu... |
| CVE-2025-69013 | MEDIUM | 4.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in jetmonsters Stratum stratum allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2025-69012 | MEDIUM | 4.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in Stephen Harris Event Organiser event-organiser allows Exploiting Incorrectly Conf... |
| CVE-2025-69010 | MEDIUM | 5.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in themebeez Themebeez Toolkit themebeez-toolkit allows Exploiting Incorrectly Confi... |
| CVE-2025-69009 | MEDIUM | 5.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in kamleshyadav Medicalequipment medicalequipment allows Exploiting Incorrectly Conf... |
| CVE-2025-69008 | MEDIUM | 5.9 | 0.2% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Inboxify Inboxify ... |
| CVE-2025-69007 | MEDIUM | 5.9 | 0.2% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Popping ... |
| CVE-2025-69006 | MEDIUM | 5.9 | 0.2% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atte Moisio AM Eve... |
| CVE-2025-68998 | MEDIUM | 5.4 | 0.1% | Dec 30, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Heateor Support Heateor Social Login heateor-social-login allows Cros... |
| CVE-2025-68997 | MEDIUM | 5.3 | 0.3% | Dec 30, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Inc... |
| CVE-2025-68995 | MEDIUM | 4.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in Premio My Sticky Elements mystickyelements allows Exploiting Incorrectly Configur... |
| CVE-2025-68994 | MEDIUM | 5.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in XforWooCommerce Product Loops for WooCommerce product-loops allows Exploiting Inc... |
| CVE-2025-68993 | MEDIUM | 5.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in XforWooCommerce Share, Print and PDF Products for WooCommerce share-print-pdf-woo... |
| CVE-2025-68992 | MEDIUM | 6.5 | 0.2% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xenioushk BWL Know... |
| CVE-2025-68991 | MEDIUM | 6.5 | 0.2% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xenioushk BWL Pro ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now