2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14630MEDIUM4.3The AdminQuickbar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-13205MEDIUM4.3The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for ...
CVE-2025-13194MEDIUM4.3The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for ...
CVE-2025-13139MEDIUM4.3The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
CVE-2025-14985MEDIUM6.4The Alpha Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alpha_block_css’ parameter i...
CVE-2025-14941MEDIUM6.4The GZSEO plugin for WordPress is vulnerable to authorization bypass leading to Stored Cross-Site Scripting in all versi...
CVE-2025-14906MEDIUM4.3The WP Youtube Video Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and...
CVE-2025-14903MEDIUM4.3The Simple Crypto Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc...
CVE-2025-14843MEDIUM5.3The Wizit Gateway for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Order Cancellation in ...
CVE-2025-14797MEDIUM5.4The Same Category Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget title placehold...
CVE-2025-14629MEDIUM5.3The Alchemist Ajax Upload plugin for WordPress is vulnerable to unauthorized media file deletion due to a missing capabi...
CVE-2025-14609MEDIUM5.3The Wise Analytics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1...
CVE-2025-13676MEDIUM6.1The JustClick registration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a...
CVE-2025-13374CRITICAL9.8The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ...
CVE-2025-12836MEDIUM6.4The VK Google Job Posting Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Descript...
CVE-2025-13952CRITICAL9.8A web page that contains unusual GPU shader code is loaded from the Internet into the GPU compiler process triggers a wr...
CVE-2025-12780Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-70458MEDIUM5.4A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sou...
CVE-2025-70457CRITICAL9.8A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/up...
CVE-2025-52026HIGH7.5An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend...
CVE-2025-52025CRITICAL9.4An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backen...
CVE-2025-52024CRITICAL9.4A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testin...
CVE-2025-52023MEDIUM5.3A vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to t...
CVE-2025-52022MEDIUM5.3A vulnerability in the PHP backend of gemsloyalty.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers ...
CVE-2025-67264HIGH7.8An OS command injection vulnerability in the com.sprd.engineermode component in Doogee Note59, Note59 Pro, and Note59 Pr...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now