2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-68989MEDIUM4.3Insertion of Sensitive Information Into Sent Data vulnerability in Renzo Johnson contact-form-7-mailchimp-extension cont...
CVE-2025-68988MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in o2oe E-Invoice App Malaysia ...
CVE-2025-68982MEDIUM5.3Missing Authorization vulnerability in designthemes DesignThemes LMS Addon designthemes-lms-addon allows Exploiting Inco...
CVE-2025-68981MEDIUM5.3Missing Authorization vulnerability in designthemes HomeFix Elementor Portfolio homefix-ele-portfolio allows Exploiting ...
CVE-2025-68980MEDIUM5.3Missing Authorization vulnerability in designthemes WeDesignTech Portfolio wedesigntech-portfolio allows Exploiting Inco...
CVE-2025-68979MEDIUM5.3Authorization Bypass Through User-Controlled Key vulnerability in SimpleCalendar Google Calendar Events google-calendar-...
CVE-2025-68978MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Desig...
CVE-2025-68977MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Desig...
CVE-2025-68976MEDIUM5.4Missing Authorization vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploiting Incorrectly Configured...
CVE-2025-68975MEDIUM4.3Authorization Bypass Through User-Controlled Key vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploi...
CVE-2025-68974MEDIUM6.6Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-15355MEDIUM6.1ISOinsight developed by NetVision Information has a Reflected Cross-site Scripting vulnerability, allowing unauthenticat...
CVE-2025-15222MEDIUM5A vulnerability has been found in Dromara Sa-Token up to 1.44.0. This issue affects the function ObjectInputStream.readO...
CVE-2025-14313MEDIUM6.1The Advance WP Query Search Filter WordPress plugin through 1.0.10 does not sanitise and escape a parameter before outpu...
CVE-2025-14312MEDIUM6.1The Advance WP Query Search Filter WordPress plugin through 1.0.10 does not sanitise and escape a parameter before outpu...
CVE-2025-15221MEDIUM5.4A flaw has been found in SohuTV CacheCloud up to 3.2.0. This vulnerability affects the function index of the file src/ma...
CVE-2025-15220MEDIUM6.1A vulnerability was detected in SohuTV CacheCloud up to 3.2.0. This affects the function init of the file src/main/java/...
CVE-2025-15219MEDIUM5.4A security vulnerability has been detected in SohuTV CacheCloud up to 3.2.0. Affected by this issue is the function doMa...
CVE-2025-15214MEDIUM4.8A vulnerability was found in Campcodes Park Ticketing System 1.0. The impacted element is the function save_pricing of t...
CVE-2025-15213MEDIUM4.3A vulnerability has been found in code-projects Student File Management System 1.0. The affected element is an unknown f...
CVE-2025-68499MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs...
CVE-2025-68498MEDIUM6.5Missing Authorization vulnerability in Crocoblock JetTabs jet-tabs allows Exploiting Incorrectly Configured Access Contr...
CVE-2025-68120MEDIUM5.4To prevent unexpected untrusted code execution, the Visual Studio Code Go extension is now disabled in Restricted Mode.
CVE-2025-68040MEDIUM6.5Insertion of Sensitive Information Into Sent Data vulnerability in weDevs WP Project Manager wedevs-project-manager allo...
CVE-2025-15284MEDIUM6.3Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1. Summary...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now