2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62762 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in photoboxone SMTP Mail smtp-mail allows Cross Site Request Forgery.Thi... |
| CVE-2025-62740 | MEDIUM | 5.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in Mario Peshev WP-CRM System wp-crm-system allows Exploiting Incorrectly Configured... |
| CVE-2025-62739 | MEDIUM | 6.5 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in SaifuMak Add Custom Codes add-custom-codes allows Cross Site Request ... |
| CVE-2025-62738 | MEDIUM | 5.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in mmattax Formstack Online Forms formstack allows Exploiting Incorrectly Configured... |
| CVE-2025-62737 | MEDIUM | 5.3 | 0.2% | Dec 9, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in opicron Image Cleanup image-... |
| CVE-2025-62736 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in opicron Image Cleanup image-cleanup allows Exploiting Incorrectly Configured Acce... |
| CVE-2025-62735 | MEDIUM | 5.3 | 0.2% | Dec 9, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Joel User Spam Remover user-... |
| CVE-2025-62734 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in M.Code Media Library Downloader media-library-downloader allows Cross... |
| CVE-2025-62733 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ProteusThemes Custom Sidebars by ProteusThemes custom-sidebars-by-pro... |
| CVE-2025-62153 | MEDIUM | 5.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in Graham Quick Interest Slider quick-interest-slider allows Exploiting Incorrectly ... |
| CVE-2025-62152 | MEDIUM | 5.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in ConveyThis ConveyThis conveythis-translate allows Exploiting Incorrectly Configur... |
| CVE-2025-62151 | MEDIUM | 5.3 | 0.3% | Dec 9, 2025 | Missing Authorization vulnerability in Virtuaria Virtuaria PagBank / PagSeguro para Woocommerce virtuaria-pagseguro allo... |
| CVE-2025-62109 | MEDIUM | 5.3 | 0.2% | Dec 9, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in INFINITUM FORM Geo Controller cf-geoplugin allows Ret... |
| CVE-2025-62103 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in wpmediadownload Media Library File Download media-download allows Cro... |
| CVE-2025-62102 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in apasionados DoFollow Case by Case dofollow-case-by-case allows Cross ... |
| CVE-2025-62100 | MEDIUM | 5.3 | 0.3% | Dec 9, 2025 | Missing Authorization vulnerability in themerain ThemeRain Core themerain-core allows Exploiting Incorrectly Configured ... |
| CVE-2025-62090 | MEDIUM | 6.5 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in Jegstudio Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons g... |
| CVE-2025-62086 | MEDIUM | 5.4 | 0.3% | Dec 9, 2025 | Missing Authorization vulnerability in akazanstev Яндекс Доставка (Boxberry) boxberry allows Exploiting Incorrectly Conf... |
| CVE-2025-62085 | MEDIUM | 5.3 | 0.3% | Dec 9, 2025 | Missing Authorization vulnerability in Bertha AI – Andrew Palmer BERTHA AI bertha-ai-free allows Exploiting Incorrectly ... |
| CVE-2025-62082 | MEDIUM | 6.5 | 0.2% | Dec 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nasir Uddin Generi... |
| CVE-2025-61074 | MEDIUM | 4.6 | 0.3% | Dec 9, 2025 | A stored Cross Site Scripting (XSS) vulnerability in the bulletin board (SchwarzeBrett) in adata Software GmbH Mitarbeit... |
| CVE-2025-59132 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Badi Jones Duplicate Content Cure duplicate-content-cure allows Cross... |
| CVE-2025-59029 | MEDIUM | 5.3 | 0.3% | Dec 9, 2025 | An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the... |
| CVE-2025-49350 | MEDIUM | 4.3 | 0.3% | Dec 9, 2025 | Missing Authorization vulnerability in marcoingraiti Actionwear products sync actionwear-products-sync allows Exploiting... |
| CVE-2025-49348 | MEDIUM | 5.3 | 0.3% | Dec 9, 2025 | Missing Authorization vulnerability in Hype Hype pico allows Exploiting Incorrectly Configured Access Control Security L... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now