2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13621 | MEDIUM | 6.1 | 0.1% | Dec 5, 2025 | The dream gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-13528 | MEDIUM | 5.3 | 0.3% | Dec 5, 2025 | The Feedback Modal for Website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi... |
| CVE-2025-13512 | MEDIUM | 6.1 | 0.2% | Dec 5, 2025 | The CoSign Single Signon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SEL... |
| CVE-2025-13360 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The Quantic Social Image Hover plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a... |
| CVE-2025-13144 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The ContentStudio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-12370 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | The Takeads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.13. Thi... |
| CVE-2025-12368 | MEDIUM | 6.4 | 0.2% | Dec 5, 2025 | The Sermon Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sermon-views` shortcode in... |
| CVE-2025-12191 | MEDIUM | 5.4 | 0.1% | Dec 5, 2025 | The PDF Catalog for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pdfcatalog' A... |
| CVE-2025-12190 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The Image Optimizer by wps.sk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an... |
| CVE-2025-12165 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | The Webcake – Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a miss... |
| CVE-2025-12163 | MEDIUM | 6.4 | 0.3% | Dec 5, 2025 | The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up ... |
| CVE-2025-12133 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | The EPROLO Dropshipping plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil... |
| CVE-2025-12128 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The Hide Categories Or Products On Shop Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver... |
| CVE-2025-12124 | MEDIUM | 4.4 | 0.2% | Dec 5, 2025 | The FitVids for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve... |
| CVE-2025-10055 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The Time Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2... |
| CVE-2025-32901 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | In KDE Connect before 1.33.0 on Android, malicious device IDs (sent via broadcast UDP) could cause an application crash. |
| CVE-2025-32899 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | In KDE Connect before 1.33.0 on Android, a packet can be crafted that causes two paired devices to unpair. Specifically,... |
| CVE-2025-32898 | MEDIUM | 4.7 | 0.1% | Dec 5, 2025 | The KDE Connect verification-code protocol before 2025-04-18 uses only 8 characters and therefore allows brute-force att... |
| CVE-2025-13494 | MEDIUM | 5.3 | 0.2% | Dec 5, 2025 | The SSP Debug plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
| CVE-2025-13362 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The Norby AI plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.... |
| CVE-2025-13312 | MEDIUM | 5.3 | 0.2% | Dec 5, 2025 | The CRM Memberships plugin for WordPress is vulnerable to unauthorized membership tag creation due to a missing capabili... |
| CVE-2025-13006 | MEDIUM | 5.3 | 0.2% | Dec 5, 2025 | The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in a... |
| CVE-2025-12417 | MEDIUM | 6.4 | 0.2% | Dec 5, 2025 | The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2025-27389 | MEDIUM | 5.1 | 0.1% | Dec 5, 2025 | A flaw exists in the verification of application installation sources within ColorOS. Under specific conditions, this is... |
| CVE-2025-12804 | MEDIUM | 6.4 | 0.2% | Dec 5, 2025 | The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bookingcalendar' ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now