2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6461 | MEDIUM | 4.3 | 0.2% | Jan 25, 2026 | The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all vers... |
| CVE-2025-13920 | MEDIUM | 5.3 | 0.7% | Jan 24, 2026 | The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc... |
| CVE-2025-15516 | MEDIUM | 4.3 | 0.2% | Jan 24, 2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca... |
| CVE-2025-14907 | MEDIUM | 4.3 | 0.1% | Jan 24, 2026 | The Moderate Selected Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2025-14630 | MEDIUM | 4.3 | 0.2% | Jan 24, 2026 | The AdminQuickbar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-13205 | MEDIUM | 4.3 | 0.1% | Jan 24, 2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for ... |
| CVE-2025-13194 | MEDIUM | 4.3 | 0.1% | Jan 24, 2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for ... |
| CVE-2025-13139 | MEDIUM | 4.3 | 0.1% | Jan 24, 2026 | The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all... |
| CVE-2025-14985 | MEDIUM | 6.4 | 0.2% | Jan 24, 2026 | The Alpha Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alpha_block_css’ parameter i... |
| CVE-2025-14941 | MEDIUM | 6.4 | 0.3% | Jan 24, 2026 | The GZSEO plugin for WordPress is vulnerable to authorization bypass leading to Stored Cross-Site Scripting in all versi... |
| CVE-2025-14906 | MEDIUM | 4.3 | 0.1% | Jan 24, 2026 | The WP Youtube Video Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and... |
| CVE-2025-14903 | MEDIUM | 4.3 | 0.2% | Jan 24, 2026 | The Simple Crypto Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc... |
| CVE-2025-14843 | MEDIUM | 5.3 | 0.3% | Jan 24, 2026 | The Wizit Gateway for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Order Cancellation in ... |
| CVE-2025-14797 | MEDIUM | 5.4 | 0.2% | Jan 24, 2026 | The Same Category Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget title placehold... |
| CVE-2025-14629 | MEDIUM | 5.3 | 0.3% | Jan 24, 2026 | The Alchemist Ajax Upload plugin for WordPress is vulnerable to unauthorized media file deletion due to a missing capabi... |
| CVE-2025-14609 | MEDIUM | 5.3 | 0.3% | Jan 24, 2026 | The Wise Analytics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1... |
| CVE-2025-13676 | MEDIUM | 6.1 | 0.3% | Jan 24, 2026 | The JustClick registration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a... |
| CVE-2025-13374 | CRITICAL | 9.8 | 1.1% | Jan 24, 2026 | The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ... |
| CVE-2025-12836 | MEDIUM | 6.4 | 0.2% | Jan 24, 2026 | The VK Google Job Posting Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Descript... |
| CVE-2025-13952 | CRITICAL | 9.8 | 0.4% | Jan 24, 2026 | A web page that contains unusual GPU shader code is loaded from the Internet into the GPU compiler process triggers a wr... |
| CVE-2025-12780 | — | — | — | Jan 23, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-70458 | MEDIUM | 5.4 | 0.2% | Jan 23, 2026 | A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sou... |
| CVE-2025-70457 | CRITICAL | 9.8 | 0.8% | Jan 23, 2026 | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/up... |
| CVE-2025-52026 | HIGH | 7.5 | 0.3% | Jan 23, 2026 | An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend... |
| CVE-2025-52025 | CRITICAL | 9.4 | 0.3% | Jan 23, 2026 | An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backen... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now