2025 CVE Vulnerabilities
45,264 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6687 | MEDIUM | 5.4 | 0.2% | Jul 2, 2025 | The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic... |
| CVE-2025-6686 | MEDIUM | 5.4 | 0.2% | Jul 2, 2025 | The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic... |
| CVE-2025-6459 | HIGH | 8.8 | 0.2% | Jul 2, 2025 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Cross-Site Reques... |
| CVE-2025-6437 | HIGH | 7.5 | 0.3% | Jul 2, 2025 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via... |
| CVE-2025-5817 | HIGH | 7.2 | 0.2% | Jul 2, 2025 | The Amazon Products to WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up ... |
| CVE-2025-5746 | CRITICAL | 9.8 | 0.6% | Jul 2, 2025 | The Drag and Drop Multiple File Upload (Pro) - WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads ... |
| CVE-2025-5339 | HIGH | 7.5 | 0.3% | Jul 2, 2025 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL In... |
| CVE-2025-5014 | HIGH | 8.8 | 0.7% | Jul 2, 2025 | The Home Villas | Real Estate WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuff... |
| CVE-2025-52925 | MEDIUM | 5 | 0.1% | Jul 2, 2025 | In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka S... |
| CVE-2025-4689 | CRITICAL | 9.8 | 0.5% | Jul 2, 2025 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclus... |
| CVE-2025-4654 | LOW | 3.7 | 0.2% | Jul 2, 2025 | The Soumettre.fr plugin for WordPress is vulnerable to unauthorized access and modification of data due to a improper au... |
| CVE-2025-4381 | HIGH | 7.5 | 0.3% | Jul 2, 2025 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via... |
| CVE-2025-4380 | CRITICAL | 9.8 | 28.2% | Jul 2, 2025 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclus... |
| CVE-2025-3848 | — | — | — | Jul 2, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-25171. Reason: This candidate is a ... |
| CVE-2025-5692 | MEDIUM | 4.3 | 0.2% | Jul 2, 2025 | The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to unauthorized access due to a missing capabili... |
| CVE-2025-36630 | HIGH | 7.1 | 0.2% | Jul 2, 2025 | In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrit... |
| CVE-2025-49741 | HIGH | 7.5 | 3.4% | Jul 1, 2025 | No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a ... |
| CVE-2025-52101 | CRITICAL | 9.8 | 0.4% | Jul 1, 2025 | linjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attacke... |
| CVE-2025-45006 | CRITICAL | 9.1 | 0.4% | Jul 1, 2025 | Improper mstatus.SUM bit retention (non-zero) in Open-Source RISC-V Processor commit f517abb violates privileged spec co... |
| CVE-2025-6600 | MEDIUM | 4.3 | 0.3% | Jul 1, 2025 | An exposure of sensitive information vulnerability was identified in GitHub Enterprise Server that could allow an attack... |
| CVE-2025-53104 | CRITICAL | 9.1 | 1.2% | Jul 1, 2025 | gluestack-ui is a library of copy-pasteable components & patterns crafted with Tailwind CSS (NativeWind). Prior to commi... |
| CVE-2025-48379 | MEDIUM | 5.5 | 0.3% | Jul 1, 2025 | Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a ... |
| CVE-2025-46259 | MEDIUM | 5.4 | 0.3% | Jul 1, 2025 | Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows Exploiting Incorrect... |
| CVE-2025-27153 | MEDIUM | 6.5 | 0.2% | Jul 1, 2025 | Escalade GLPI plugin is a ticket escalation process helper for GLPI. Prior to version 2.9.11, there is an improper acces... |
| CVE-2025-53107 | HIGH | 7.5 | 22.1% | Jul 1, 2025 | @cyanheads/git-mcp-server is an MCP server designed to interact with Git repositories. Prior to version 2.1.5, there is ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now