2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68989 | MEDIUM | 4.3 | 0.2% | Dec 30, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Renzo Johnson contact-form-7-mailchimp-extension cont... |
| CVE-2025-68988 | MEDIUM | 5.3 | 0.3% | Dec 30, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in o2oe E-Invoice App Malaysia ... |
| CVE-2025-68982 | MEDIUM | 5.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in designthemes DesignThemes LMS Addon designthemes-lms-addon allows Exploiting Inco... |
| CVE-2025-68981 | MEDIUM | 5.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in designthemes HomeFix Elementor Portfolio homefix-ele-portfolio allows Exploiting ... |
| CVE-2025-68980 | MEDIUM | 5.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in designthemes WeDesignTech Portfolio wedesigntech-portfolio allows Exploiting Inco... |
| CVE-2025-68979 | MEDIUM | 5.3 | 0.2% | Dec 30, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in SimpleCalendar Google Calendar Events google-calendar-... |
| CVE-2025-68978 | MEDIUM | 6.5 | 0.2% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Desig... |
| CVE-2025-68977 | MEDIUM | 6.5 | 0.2% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Desig... |
| CVE-2025-68976 | MEDIUM | 5.4 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploiting Incorrectly Configured... |
| CVE-2025-68975 | MEDIUM | 4.3 | 0.3% | Dec 30, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploi... |
| CVE-2025-68974 | MEDIUM | 6.6 | 0.4% | Dec 30, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-15355 | MEDIUM | 6.1 | 0.2% | Dec 30, 2025 | ISOinsight developed by NetVision Information has a Reflected Cross-site Scripting vulnerability, allowing unauthenticat... |
| CVE-2025-15222 | MEDIUM | 5 | 0.2% | Dec 30, 2025 | A vulnerability has been found in Dromara Sa-Token up to 1.44.0. This issue affects the function ObjectInputStream.readO... |
| CVE-2025-14313 | MEDIUM | 6.1 | 0.1% | Dec 30, 2025 | The Advance WP Query Search Filter WordPress plugin through 1.0.10 does not sanitise and escape a parameter before outpu... |
| CVE-2025-14312 | MEDIUM | 6.1 | 0.1% | Dec 30, 2025 | The Advance WP Query Search Filter WordPress plugin through 1.0.10 does not sanitise and escape a parameter before outpu... |
| CVE-2025-15221 | MEDIUM | 5.4 | 0.2% | Dec 30, 2025 | A flaw has been found in SohuTV CacheCloud up to 3.2.0. This vulnerability affects the function index of the file src/ma... |
| CVE-2025-15220 | MEDIUM | 6.1 | 0.3% | Dec 30, 2025 | A vulnerability was detected in SohuTV CacheCloud up to 3.2.0. This affects the function init of the file src/main/java/... |
| CVE-2025-15219 | MEDIUM | 5.4 | 0.2% | Dec 30, 2025 | A security vulnerability has been detected in SohuTV CacheCloud up to 3.2.0. Affected by this issue is the function doMa... |
| CVE-2025-15214 | MEDIUM | 4.8 | 0.3% | Dec 30, 2025 | A vulnerability was found in Campcodes Park Ticketing System 1.0. The impacted element is the function save_pricing of t... |
| CVE-2025-15213 | MEDIUM | 4.3 | 0.3% | Dec 30, 2025 | A vulnerability has been found in code-projects Student File Management System 1.0. The affected element is an unknown f... |
| CVE-2025-68499 | MEDIUM | 6.5 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs... |
| CVE-2025-68498 | MEDIUM | 6.5 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in Crocoblock JetTabs jet-tabs allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2025-68120 | MEDIUM | 5.4 | 0.4% | Dec 30, 2025 | To prevent unexpected untrusted code execution, the Visual Studio Code Go extension is now disabled in Restricted Mode. |
| CVE-2025-68040 | MEDIUM | 6.5 | 0.2% | Dec 30, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in weDevs WP Project Manager wedevs-project-manager allo... |
| CVE-2025-15284 | MEDIUM | 6.3 | 0.4% | Dec 29, 2025 | Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1. Summary... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now