2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12093MEDIUM5.3The Voidek Employee Portal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o...
CVE-2025-66270MEDIUM4.7The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect ...
CVE-2025-32900MEDIUM4.3In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the di...
CVE-2025-13860MEDIUM6.4The Easy Jump Links Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `h_tags` parameter i...
CVE-2025-13625MEDIUM6.1The WP-SOS-Donate Donation Sidebar Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVE...
CVE-2025-13623MEDIUM6.1The Twitscription plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO in al...
CVE-2025-13622MEDIUM6.1The Jabbernotification plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO ...
CVE-2025-13621MEDIUM6.1The dream gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-13528MEDIUM5.3The Feedback Modal for Website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi...
CVE-2025-13512MEDIUM6.1The CoSign Single Signon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SEL...
CVE-2025-13360MEDIUM4.3The Quantic Social Image Hover plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2025-13144MEDIUM4.3The ContentStudio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-12370MEDIUM4.3The Takeads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.13. Thi...
CVE-2025-12368MEDIUM6.4The Sermon Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sermon-views` shortcode in...
CVE-2025-12191MEDIUM5.4The PDF Catalog for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pdfcatalog' A...
CVE-2025-12190MEDIUM4.3The Image Optimizer by wps.sk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an...
CVE-2025-12165MEDIUM4.3The Webcake – Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a miss...
CVE-2025-12163MEDIUM6.4The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up ...
CVE-2025-12133MEDIUM4.3The EPROLO Dropshipping plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil...
CVE-2025-12128MEDIUM4.3The Hide Categories Or Products On Shop Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver...
CVE-2025-12124MEDIUM4.4The FitVids for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve...
CVE-2025-10055MEDIUM4.3The Time Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2...
CVE-2025-32901MEDIUM4.3In KDE Connect before 1.33.0 on Android, malicious device IDs (sent via broadcast UDP) could cause an application crash.
CVE-2025-32899MEDIUM4.3In KDE Connect before 1.33.0 on Android, a packet can be crafted that causes two paired devices to unpair. Specifically,...
CVE-2025-32898MEDIUM4.7The KDE Connect verification-code protocol before 2025-04-18 uses only 8 characters and therefore allows brute-force att...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now