2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12093 | MEDIUM | 5.3 | 0.2% | Dec 5, 2025 | The Voidek Employee Portal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o... |
| CVE-2025-66270 | MEDIUM | 4.7 | 0.2% | Dec 5, 2025 | The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect ... |
| CVE-2025-32900 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the di... |
| CVE-2025-13860 | MEDIUM | 6.4 | 0.2% | Dec 5, 2025 | The Easy Jump Links Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `h_tags` parameter i... |
| CVE-2025-13625 | MEDIUM | 6.1 | 0.2% | Dec 5, 2025 | The WP-SOS-Donate Donation Sidebar Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVE... |
| CVE-2025-13623 | MEDIUM | 6.1 | 0.2% | Dec 5, 2025 | The Twitscription plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO in al... |
| CVE-2025-13622 | MEDIUM | 6.1 | 0.2% | Dec 5, 2025 | The Jabbernotification plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO ... |
| CVE-2025-13621 | MEDIUM | 6.1 | 0.1% | Dec 5, 2025 | The dream gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-13528 | MEDIUM | 5.3 | 0.3% | Dec 5, 2025 | The Feedback Modal for Website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi... |
| CVE-2025-13512 | MEDIUM | 6.1 | 0.2% | Dec 5, 2025 | The CoSign Single Signon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SEL... |
| CVE-2025-13360 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The Quantic Social Image Hover plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a... |
| CVE-2025-13144 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The ContentStudio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-12370 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | The Takeads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.13. Thi... |
| CVE-2025-12368 | MEDIUM | 6.4 | 0.2% | Dec 5, 2025 | The Sermon Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sermon-views` shortcode in... |
| CVE-2025-12191 | MEDIUM | 5.4 | 0.1% | Dec 5, 2025 | The PDF Catalog for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pdfcatalog' A... |
| CVE-2025-12190 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The Image Optimizer by wps.sk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an... |
| CVE-2025-12165 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | The Webcake – Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a miss... |
| CVE-2025-12163 | MEDIUM | 6.4 | 0.4% | Dec 5, 2025 | The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up ... |
| CVE-2025-12133 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | The EPROLO Dropshipping plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil... |
| CVE-2025-12128 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The Hide Categories Or Products On Shop Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver... |
| CVE-2025-12124 | MEDIUM | 4.4 | 0.2% | Dec 5, 2025 | The FitVids for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve... |
| CVE-2025-10055 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The Time Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2... |
| CVE-2025-32901 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | In KDE Connect before 1.33.0 on Android, malicious device IDs (sent via broadcast UDP) could cause an application crash. |
| CVE-2025-32899 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | In KDE Connect before 1.33.0 on Android, a packet can be crafted that causes two paired devices to unpair. Specifically,... |
| CVE-2025-32898 | MEDIUM | 4.7 | 0.1% | Dec 5, 2025 | The KDE Connect verification-code protocol before 2025-04-18 uses only 8 characters and therefore allows brute-force att... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now