2025 CVE Vulnerabilities

45,264 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-6687MEDIUM5.4The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic...
CVE-2025-6686MEDIUM5.4The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic...
CVE-2025-6459HIGH8.8The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Cross-Site Reques...
CVE-2025-6437HIGH7.5The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via...
CVE-2025-5817HIGH7.2The Amazon Products to WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up ...
CVE-2025-5746CRITICAL9.8The Drag and Drop Multiple File Upload (Pro) - WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads ...
CVE-2025-5339HIGH7.5The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL In...
CVE-2025-5014HIGH8.8The Home Villas | Real Estate WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuff...
CVE-2025-52925MEDIUM5In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka S...
CVE-2025-4689CRITICAL9.8The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclus...
CVE-2025-4654LOW3.7The Soumettre.fr plugin for WordPress is vulnerable to unauthorized access and modification of data due to a improper au...
CVE-2025-4381HIGH7.5The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via...
CVE-2025-4380CRITICAL9.8The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclus...
CVE-2025-3848Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-25171. Reason: This candidate is a ...
CVE-2025-5692MEDIUM4.3The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to unauthorized access due to a missing capabili...
CVE-2025-36630HIGH7.1In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrit...
CVE-2025-49741HIGH7.5No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a ...
CVE-2025-52101CRITICAL9.8linjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attacke...
CVE-2025-45006CRITICAL9.1Improper mstatus.SUM bit retention (non-zero) in Open-Source RISC-V Processor commit f517abb violates privileged spec co...
CVE-2025-6600MEDIUM4.3An exposure of sensitive information vulnerability was identified in GitHub Enterprise Server that could allow an attack...
CVE-2025-53104CRITICAL9.1gluestack-ui is a library of copy-pasteable components & patterns crafted with Tailwind CSS (NativeWind). Prior to commi...
CVE-2025-48379MEDIUM5.5Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a ...
CVE-2025-46259MEDIUM5.4Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows Exploiting Incorrect...
CVE-2025-27153MEDIUM6.5Escalade GLPI plugin is a ticket escalation process helper for GLPI. Prior to version 2.9.11, there is an improper acces...
CVE-2025-53107HIGH7.5@cyanheads/git-mcp-server is an MCP server designed to interact with Git repositories. Prior to version 2.1.5, there is ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now