2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14630 | MEDIUM | 4.3 | 0.2% | Jan 24, 2026 | The AdminQuickbar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-13205 | MEDIUM | 4.3 | 0.1% | Jan 24, 2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for ... |
| CVE-2025-13194 | MEDIUM | 4.3 | 0.1% | Jan 24, 2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for ... |
| CVE-2025-13139 | MEDIUM | 4.3 | 0.1% | Jan 24, 2026 | The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all... |
| CVE-2025-14985 | MEDIUM | 6.4 | 0.2% | Jan 24, 2026 | The Alpha Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alpha_block_css’ parameter i... |
| CVE-2025-14941 | MEDIUM | 6.4 | 0.3% | Jan 24, 2026 | The GZSEO plugin for WordPress is vulnerable to authorization bypass leading to Stored Cross-Site Scripting in all versi... |
| CVE-2025-14906 | MEDIUM | 4.3 | 0.1% | Jan 24, 2026 | The WP Youtube Video Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and... |
| CVE-2025-14903 | MEDIUM | 4.3 | 0.2% | Jan 24, 2026 | The Simple Crypto Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc... |
| CVE-2025-14843 | MEDIUM | 5.3 | 0.3% | Jan 24, 2026 | The Wizit Gateway for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Order Cancellation in ... |
| CVE-2025-14797 | MEDIUM | 5.4 | 0.2% | Jan 24, 2026 | The Same Category Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget title placehold... |
| CVE-2025-14629 | MEDIUM | 5.3 | 0.3% | Jan 24, 2026 | The Alchemist Ajax Upload plugin for WordPress is vulnerable to unauthorized media file deletion due to a missing capabi... |
| CVE-2025-14609 | MEDIUM | 5.3 | 0.3% | Jan 24, 2026 | The Wise Analytics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1... |
| CVE-2025-13676 | MEDIUM | 6.1 | 0.3% | Jan 24, 2026 | The JustClick registration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a... |
| CVE-2025-13374 | CRITICAL | 9.8 | 1.1% | Jan 24, 2026 | The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ... |
| CVE-2025-12836 | MEDIUM | 6.4 | 0.2% | Jan 24, 2026 | The VK Google Job Posting Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Descript... |
| CVE-2025-13952 | CRITICAL | 9.8 | 0.4% | Jan 24, 2026 | A web page that contains unusual GPU shader code is loaded from the Internet into the GPU compiler process triggers a wr... |
| CVE-2025-12780 | — | — | — | Jan 23, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-70458 | MEDIUM | 5.4 | 0.2% | Jan 23, 2026 | A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sou... |
| CVE-2025-70457 | CRITICAL | 9.8 | 0.8% | Jan 23, 2026 | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/up... |
| CVE-2025-52026 | HIGH | 7.5 | 0.3% | Jan 23, 2026 | An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend... |
| CVE-2025-52025 | CRITICAL | 9.4 | 0.3% | Jan 23, 2026 | An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backen... |
| CVE-2025-52024 | CRITICAL | 9.4 | 0.4% | Jan 23, 2026 | A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testin... |
| CVE-2025-52023 | MEDIUM | 5.3 | 0.4% | Jan 23, 2026 | A vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to t... |
| CVE-2025-52022 | MEDIUM | 5.3 | 0.4% | Jan 23, 2026 | A vulnerability in the PHP backend of gemsloyalty.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers ... |
| CVE-2025-67264 | HIGH | 7.8 | 0.9% | Jan 23, 2026 | An OS command injection vulnerability in the com.sprd.engineermode component in Doogee Note59, Note59 Pro, and Note59 Pr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now