2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-6222CRITICAL9.8The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPres...
CVE-2025-5811MEDIUM5.3The Listly: Listicles For WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2025-5800MEDIUM6.4The Testimonial Post type plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ paramete...
CVE-2025-5767MEDIUM6.4The Crowdfunding for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ param...
CVE-2025-5754MEDIUM6.4The Useful Tab Block – Responsive & AMP-Compatible plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
CVE-2025-5752MEDIUM6.4The Vertical scroll image slideshow gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘w...
CVE-2025-29572Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-7660MEDIUM6.4The Map My Locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'map_my_location...
CVE-2025-7648MEDIUM6.4The Ruven Themes: Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ruven_b...
CVE-2025-7638MEDIUM4.9The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based...
CVE-2025-6813HIGH8.8The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks wi...
CVE-2025-6781MEDIUM4.3The Copymatic – AI Content Writer & Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve...
CVE-2025-6053MEDIUM6.1The Zuppler Online Ordering plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2025-5816MEDIUM4.3The Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship plugin for WordPress is vulnerable to Insecure...
CVE-2025-3740HIGH8.8The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up...
CVE-2025-7431MEDIUM4.4The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin slug setting in all ...
CVE-2025-7767MEDIUM5.4A vulnerability, which was classified as problematic, has been found in PHPGurukul Art Gallery Management System 1.1. Af...
CVE-2025-6185CRITICAL9.3Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an atta...
CVE-2025-7765CRITICAL9.8A vulnerability classified as critical was found in code-projects Online Appointment Booking System 1.0. Affected by thi...
CVE-2025-7764CRITICAL9.8A vulnerability classified as critical has been found in code-projects Online Appointment Booking System 1.0. Affected i...
CVE-2025-7763MEDIUM4.3A vulnerability, which was classified as problematic, was found in thinkgem JeeSite up to 5.12.0. Affected is the functi...
CVE-2025-7762MEDIUM6.5A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07.26A1. This issue affects some ...
CVE-2025-7759HIGH8.8A vulnerability was identified in thinkgem JeeSite up to 5.12.0. This vulnerability affects unknown code of the file mod...
CVE-2025-7758HIGH8.8A vulnerability, which was classified as critical, has been found in TOTOLINK T6 up to 4.1.5cu.748_B20211015. Affected b...
CVE-2025-7398CRITICAL9.1Brocade ASCG before 3.3.0 allows for the use of medium strength cryptography algorithms on internal ports ports 9000 and...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now