2025 CVE Vulnerabilities
45,139 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64630 | MEDIUM | 4.9 | 0.3% | Dec 16, 2025 | Missing Authorization vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Exploiting In... |
| CVE-2025-64253 | MEDIUM | 4.9 | 0.4% | Dec 16, 2025 | Path Traversal: '.../...//' vulnerability in WordPress.org Health Check & Troubleshooting health-check allows Path Trave... |
| CVE-2025-64251 | MEDIUM | 4.9 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in azzaroco Ultimate Learning Pro indeed-learning-pro allows Exploiting Incorrectly ... |
| CVE-2025-64250 | MEDIUM | 4.7 | 0.2% | Dec 16, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wpWax Directorist directorist allows Phishing.This ... |
| CVE-2025-64249 | MEDIUM | 5.3 | 0.3% | Dec 16, 2025 | Missing Authorization vulnerability in WP-EXPERTS.IN Protect WP Admin protect-wp-admin allows Exploiting Incorrectly Con... |
| CVE-2025-64248 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in emarket-design Request a Quote request-a-quote allows Exploiting Incorrectly Conf... |
| CVE-2025-64247 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in edmon.parker Read More & Accordion expand-maker allows Exploiting Incorrectly Con... |
| CVE-2025-64246 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in netopsae Accessibility by AudioEye accessibility-by-audioeye allows Exploiting In... |
| CVE-2025-64245 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in ryanpcmcquen Import external attachments import-external-attachments allows Explo... |
| CVE-2025-64244 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in Codexpert, Inc Restrict Elementor Widgets, Columns and Sections restrict-elemento... |
| CVE-2025-64243 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Ac... |
| CVE-2025-64242 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in Merv Barrett Easy Property Listings easy-property-listings allows Exploiting Inco... |
| CVE-2025-64241 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in Imtiaz Rayhan WP Coupons and Deals wp-coupons-and-deals allows Exploiting Incorre... |
| CVE-2025-64240 | MEDIUM | 4.3 | 0.1% | Dec 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in freshchat Freshchat freshchat allows Cross Site Request Forgery.This ... |
| CVE-2025-64239 | MEDIUM | 4.3 | 0.1% | Dec 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Yoav Farhi RTL Tester rtl-tester allows Cross Site Request Forgery.Th... |
| CVE-2025-64238 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in NicolasKulka WPS Bidouille wps-bidouille allows Exploiting Incorrectly Configured... |
| CVE-2025-64237 | MEDIUM | 4.3 | 0.1% | Dec 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Graham Quick Interest Slider quick-interest-slider allows Cross Site ... |
| CVE-2025-59009 | MEDIUM | 4.3 | 0.1% | Dec 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Astoundify Listify listify allows Cross Site Request Forgery.This iss... |
| CVE-2025-59001 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in ThemeNectar Salient Core salient-core allows Exploiting Incorrectly Configured Ac... |
| CVE-2025-58999 | MEDIUM | 4.3 | 0.1% | Dec 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donation... |
| CVE-2025-54045 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in CreativeMindsSolutions CM On Demand Search And Replace cm-on-demand-search-and-re... |
| CVE-2025-54005 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in sonalsinha21 SKT Page Builder skt-builder allows Exploiting Incorrectly Configure... |
| CVE-2025-13231 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | The Fancy Product Designer plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and ... |
| CVE-2025-13439 | MEDIUM | 5.9 | 0.3% | Dec 16, 2025 | The Fancy Product Designer plugin for WordPress is vulnerable to Information Disclosure and PHAR Deserialization in all ... |
| CVE-2025-11991 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to unauthorized modification of data... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now