2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12971 | MEDIUM | 4.3 | 0.2% | Nov 27, 2025 | The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vul... |
| CVE-2025-59454 | MEDIUM | 4.3 | 0.3% | Nov 27, 2025 | In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetworkACLs - listResour... |
| CVE-2025-59302 | MEDIUM | 4.7 | 0.4% | Nov 27, 2025 | In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following ... |
| CVE-2025-54057 | MEDIUM | 6.1 | 0.6% | Nov 27, 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache SkyWalking. This ... |
| CVE-2025-13742 | MEDIUM | 6.1 | 0.2% | Nov 27, 2025 | Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used ... |
| CVE-2025-10476 | MEDIUM | 4.3 | 0.2% | Nov 27, 2025 | The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2025-59026 | MEDIUM | 5.4 | 0.2% | Nov 27, 2025 | Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintend... |
| CVE-2025-59025 | MEDIUM | 6.1 | 0.2% | Nov 27, 2025 | Malicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the us... |
| CVE-2025-30190 | MEDIUM | 5.4 | 0.2% | Nov 27, 2025 | Malicious content at office documents can be used to inject script code when editing a document. Unintended actions can ... |
| CVE-2025-30186 | MEDIUM | 5.4 | 0.2% | Nov 27, 2025 | Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintend... |
| CVE-2025-13381 | MEDIUM | 5.3 | 0.2% | Nov 27, 2025 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due t... |
| CVE-2025-13378 | MEDIUM | 6.5 | 0.2% | Nov 27, 2025 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forge... |
| CVE-2025-12584 | MEDIUM | 5.3 | 0.2% | Nov 27, 2025 | The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inc... |
| CVE-2025-13441 | MEDIUM | 5.3 | 0.2% | Nov 27, 2025 | The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versio... |
| CVE-2025-13157 | MEDIUM | 5.3 | 0.2% | Nov 27, 2025 | The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions... |
| CVE-2025-13525 | MEDIUM | 6.1 | 0.2% | Nov 27, 2025 | The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order_by' parameter i... |
| CVE-2025-13143 | MEDIUM | 4.3 | 0.1% | Nov 27, 2025 | The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Cross-Site Request Forgery i... |
| CVE-2025-12185 | MEDIUM | 4.4 | 0.2% | Nov 27, 2025 | The StaffList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to... |
| CVE-2025-12123 | MEDIUM | 6.1 | 0.2% | Nov 27, 2025 | The Customer Reviews Collector for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ... |
| CVE-2025-3784 | MEDIUM | 5.5 | 0.1% | Nov 27, 2025 | Cleartext Storage of Sensitive Information Vulnerability in GX Works2 all versions allows an attacker to disclose creden... |
| CVE-2025-12151 | MEDIUM | 6.4 | 0.2% | Nov 27, 2025 | The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'portfolio_name' parameter in... |
| CVE-2025-13762 | MEDIUM | 4.8 | 0.1% | Nov 27, 2025 | Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial... |
| CVE-2025-12713 | MEDIUM | 6.4 | 0.2% | Nov 27, 2025 | The Soundslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the soundslides shortcode in all v... |
| CVE-2025-12712 | MEDIUM | 6.4 | 0.2% | Nov 27, 2025 | The Shouty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shouty shortcode in all versions up... |
| CVE-2025-12670 | MEDIUM | 6.4 | 0.2% | Nov 27, 2025 | The wp-twitpic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'twitpic... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now