2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12537 | MEDIUM | 6.4 | 0.2% | Dec 14, 2025 | The Addon Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to... |
| CVE-2025-67897 | MEDIUM | 5.3 | 0.3% | Dec 14, 2025 | In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take adva... |
| CVE-2025-9873 | MEDIUM | 6.4 | 0.3% | Dec 13, 2025 | The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,... |
| CVE-2025-9856 | MEDIUM | 6.4 | 0.3% | Dec 13, 2025 | The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to St... |
| CVE-2025-9488 | MEDIUM | 6.4 | 0.3% | Dec 13, 2025 | The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data’ parameter in all ve... |
| CVE-2025-9207 | MEDIUM | 5.3 | 0.4% | Dec 13, 2025 | The TI WooCommerce Wishlist plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2... |
| CVE-2025-9116 | MEDIUM | 5.8 | 0.1% | Dec 13, 2025 | The WPS Visitor Counter WordPress plugin through 1.4.8 does not escape the $_SERVER['REQUEST_URI'] parameter before outp... |
| CVE-2025-8780 | MEDIUM | 6.4 | 0.2% | Dec 13, 2025 | The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Hero ... |
| CVE-2025-8779 | MEDIUM | 6.4 | 0.2% | Dec 13, 2025 | The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2025-8687 | MEDIUM | 6.4 | 0.2% | Dec 13, 2025 | The Enter Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown and Image ... |
| CVE-2025-8617 | MEDIUM | 6.4 | 0.3% | Dec 13, 2025 | The YITH WooCommerce Quick View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yith_... |
| CVE-2025-8199 | MEDIUM | 6.4 | 0.2% | Dec 13, 2025 | The MarqueeAddons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial Marquee... |
| CVE-2025-8195 | MEDIUM | 6.4 | 0.2% | Dec 13, 2025 | The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Co... |
| CVE-2025-7960 | MEDIUM | 6.4 | 0.2% | Dec 13, 2025 | The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing... |
| CVE-2025-7058 | MEDIUM | 6.4 | 0.2% | Dec 13, 2025 | The Kingcabs theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘progressbarLayout’ parameter in a... |
| CVE-2025-36750 | MEDIUM | 5.4 | 0.1% | Dec 13, 2025 | ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the Plant Name field. A HTML payload will be di... |
| CVE-2025-36748 | MEDIUM | 5.4 | 0.1% | Dec 13, 2025 | ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the local configuration web server. The JavaScr... |
| CVE-2025-14617 | MEDIUM | 5.3 | 0.1% | Dec 13, 2025 | A vulnerability has been found in Jehovahs Witnesses JW Library App up to 15.5.1 on Android. Affected is an unknown func... |
| CVE-2025-14607 | MEDIUM | 6.3 | 0.2% | Dec 13, 2025 | A vulnerability was detected in OFFIS DCMTK up to 3.6.9. Affected by this issue is the function DcmByteString::makeDicom... |
| CVE-2025-14606 | MEDIUM | 5 | 0.2% | Dec 13, 2025 | A security vulnerability has been detected in tiny-rdm Tiny RDM up to 1.2.5. Affected by this vulnerability is the funct... |
| CVE-2025-14581 | MEDIUM | 4.3 | 0.2% | Dec 13, 2025 | The HAPPY – Helpdesk Support Ticket System plugin for WordPress is vulnerable to authorization bypass due to a missing c... |
| CVE-2025-14540 | MEDIUM | 4.3 | 0.2% | Dec 13, 2025 | The Userback plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ... |
| CVE-2025-14539 | MEDIUM | 5.4 | 0.2% | Dec 13, 2025 | The The Shortcode Ajax plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and in... |
| CVE-2025-14508 | MEDIUM | 6.5 | 0.2% | Dec 13, 2025 | The MediaCommander – Bring Folders to Media, Posts, and Pages plugin for WordPress is vulnerable to unauthorized data de... |
| CVE-2025-14477 | MEDIUM | 4.9 | 0.3% | Dec 13, 2025 | The 404 Solution plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.1.0 due to ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now