2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13621MEDIUM6.1The dream gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-13528MEDIUM5.3The Feedback Modal for Website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi...
CVE-2025-13512MEDIUM6.1The CoSign Single Signon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SEL...
CVE-2025-13360MEDIUM4.3The Quantic Social Image Hover plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2025-13144MEDIUM4.3The ContentStudio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-12370MEDIUM4.3The Takeads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.13. Thi...
CVE-2025-12368MEDIUM6.4The Sermon Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sermon-views` shortcode in...
CVE-2025-12191MEDIUM5.4The PDF Catalog for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pdfcatalog' A...
CVE-2025-12190MEDIUM4.3The Image Optimizer by wps.sk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an...
CVE-2025-12165MEDIUM4.3The Webcake – Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a miss...
CVE-2025-12163MEDIUM6.4The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up ...
CVE-2025-12133MEDIUM4.3The EPROLO Dropshipping plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil...
CVE-2025-12128MEDIUM4.3The Hide Categories Or Products On Shop Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver...
CVE-2025-12124MEDIUM4.4The FitVids for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve...
CVE-2025-10055MEDIUM4.3The Time Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2...
CVE-2025-32901MEDIUM4.3In KDE Connect before 1.33.0 on Android, malicious device IDs (sent via broadcast UDP) could cause an application crash.
CVE-2025-32899MEDIUM4.3In KDE Connect before 1.33.0 on Android, a packet can be crafted that causes two paired devices to unpair. Specifically,...
CVE-2025-32898MEDIUM4.7The KDE Connect verification-code protocol before 2025-04-18 uses only 8 characters and therefore allows brute-force att...
CVE-2025-13494MEDIUM5.3The SSP Debug plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2025-13362MEDIUM4.3The Norby AI plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0....
CVE-2025-13312MEDIUM5.3The CRM Memberships plugin for WordPress is vulnerable to unauthorized membership tag creation due to a missing capabili...
CVE-2025-13006MEDIUM5.3The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in a...
CVE-2025-12417MEDIUM6.4The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-27389MEDIUM5.1A flaw exists in the verification of application installation sources within ColorOS. Under specific conditions, this is...
CVE-2025-12804MEDIUM6.4The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bookingcalendar' ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now