2025 CVE Vulnerabilities
45,139 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66163 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Masker for Elementor masker-elementor allows Exploiting Incorrectly Con... |
| CVE-2025-66162 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Spoter for Elementor spoter-elementor allows Exploiting Incorrectly Con... |
| CVE-2025-66161 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Grider for Elementor grider-elementor allows Exploiting Incorrectly Con... |
| CVE-2025-66147 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Coder for Elementor coder-elementor allows Exploiting Incorrectly Confi... |
| CVE-2025-66134 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in NinjaTeam FileBird Pro filebird-pro allows Exploiting Incorrectly Configured Acce... |
| CVE-2025-66133 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-con... |
| CVE-2025-66132 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in FAPI Business s.r.o. FAPI Member fapi-member allows Ex... |
| CVE-2025-66131 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in yaadsarig Yaad Sarig Payment Gateway For WC yaad-sarig-payment-gateway-for-wc all... |
| CVE-2025-66130 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in etruel WP Views Counter wpecounter allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-66129 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in wppochipp Pochipp pochipp allows Exploiting Incorrectly Configured Access Control... |
| CVE-2025-66128 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in Brevo Sendinblue for WooCommerce woocommerce-sendinblue-newsletter-subscription a... |
| CVE-2025-66127 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in g5theme Essential Real Estate essential-real-estate allows Exploiting Incorrectly... |
| CVE-2025-66126 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in wowpress.host Fix Media Library wow-media-library-fix... |
| CVE-2025-66125 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Nitesh Ultimate Auction ultimate-auction allows Retr... |
| CVE-2025-66124 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in ZEEN101 Leaky Paywall leaky-paywall allows Exploiting Incorrectly Configured Acce... |
| CVE-2025-66122 | MEDIUM | 5.3 | 0.3% | Dec 16, 2025 | Missing Authorization vulnerability in Design Stylish Price List stylish-price-list allows Exploiting Incorrectly Config... |
| CVE-2025-66121 | MEDIUM | 5.3 | 0.3% | Dec 16, 2025 | Missing Authorization vulnerability in SiteGround SiteGround Security sg-security allows Exploiting Incorrectly Configur... |
| CVE-2025-66120 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in CatFolders CatFolders catfolders allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-64639 | MEDIUM | 5.3 | 0.3% | Dec 16, 2025 | Missing Authorization vulnerability in WP Compress WP Compress for MainWP wp-compress-mainwp allows Exploiting Incorrect... |
| CVE-2025-64638 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in OnPay.io OnPay.io for WooCommerce onpay-io-for-woocommerce allows Exploiting Inco... |
| CVE-2025-64635 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in Syed Balkhi Feeds for YouTube feeds-for-youtube allows Exploiting Incorrectly Con... |
| CVE-2025-64634 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in ThemeFusion Avada avada allows Accessing Functionality Not Properly Constrained b... |
| CVE-2025-64633 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in colabrio Norebro Extra no... |
| CVE-2025-64632 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in Auctollo Google XML Sitemaps google-sitemap-generator allows Exploiting Incorrect... |
| CVE-2025-64631 | MEDIUM | 4.9 | 0.3% | Dec 16, 2025 | Missing Authorization vulnerability in WC Lovers WCFM Marketplace wc-multivendor-marketplace allows Exploiting Incorrect... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now