2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6222 | CRITICAL | 9.8 | 0.6% | Jul 18, 2025 | The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPres... |
| CVE-2025-5811 | MEDIUM | 5.3 | 0.3% | Jul 18, 2025 | The Listly: Listicles For WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2025-5800 | MEDIUM | 6.4 | 0.2% | Jul 18, 2025 | The Testimonial Post type plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ paramete... |
| CVE-2025-5767 | MEDIUM | 6.4 | 0.2% | Jul 18, 2025 | The Crowdfunding for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ param... |
| CVE-2025-5754 | MEDIUM | 6.4 | 0.2% | Jul 18, 2025 | The Useful Tab Block – Responsive & AMP-Compatible plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2025-5752 | MEDIUM | 6.4 | 0.2% | Jul 18, 2025 | The Vertical scroll image slideshow gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘w... |
| CVE-2025-29572 | — | — | — | Jul 18, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-7660 | MEDIUM | 6.4 | 0.2% | Jul 18, 2025 | The Map My Locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'map_my_location... |
| CVE-2025-7648 | MEDIUM | 6.4 | 0.2% | Jul 18, 2025 | The Ruven Themes: Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ruven_b... |
| CVE-2025-7638 | MEDIUM | 4.9 | 0.3% | Jul 18, 2025 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based... |
| CVE-2025-6813 | HIGH | 8.8 | 0.4% | Jul 18, 2025 | The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks wi... |
| CVE-2025-6781 | MEDIUM | 4.3 | 0.1% | Jul 18, 2025 | The Copymatic – AI Content Writer & Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve... |
| CVE-2025-6053 | MEDIUM | 6.1 | 0.1% | Jul 18, 2025 | The Zuppler Online Ordering plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2025-5816 | MEDIUM | 4.3 | 0.2% | Jul 18, 2025 | The Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship plugin for WordPress is vulnerable to Insecure... |
| CVE-2025-3740 | HIGH | 8.8 | 0.7% | Jul 18, 2025 | The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up... |
| CVE-2025-7431 | MEDIUM | 4.4 | 0.2% | Jul 18, 2025 | The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin slug setting in all ... |
| CVE-2025-7767 | MEDIUM | 5.4 | 0.2% | Jul 18, 2025 | A vulnerability, which was classified as problematic, has been found in PHPGurukul Art Gallery Management System 1.1. Af... |
| CVE-2025-6185 | CRITICAL | 9.3 | 0.3% | Jul 18, 2025 | Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an atta... |
| CVE-2025-7765 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | A vulnerability classified as critical was found in code-projects Online Appointment Booking System 1.0. Affected by thi... |
| CVE-2025-7764 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | A vulnerability classified as critical has been found in code-projects Online Appointment Booking System 1.0. Affected i... |
| CVE-2025-7763 | MEDIUM | 4.3 | 0.4% | Jul 17, 2025 | A vulnerability, which was classified as problematic, was found in thinkgem JeeSite up to 5.12.0. Affected is the functi... |
| CVE-2025-7762 | MEDIUM | 6.5 | 3.3% | Jul 17, 2025 | A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07.26A1. This issue affects some ... |
| CVE-2025-7759 | HIGH | 8.8 | 0.3% | Jul 17, 2025 | A vulnerability was identified in thinkgem JeeSite up to 5.12.0. This vulnerability affects unknown code of the file mod... |
| CVE-2025-7758 | HIGH | 8.8 | 0.8% | Jul 17, 2025 | A vulnerability, which was classified as critical, has been found in TOTOLINK T6 up to 4.1.5cu.748_B20211015. Affected b... |
| CVE-2025-7398 | CRITICAL | 9.1 | 0.2% | Jul 17, 2025 | Brocade ASCG before 3.3.0 allows for the use of medium strength cryptography algorithms on internal ports ports 9000 and... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now