2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-59369MEDIUM5.9A SQL injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnera...
CVE-2025-59368MEDIUM6An integer underflow vulnerability has been identified in Aicloud. An authenticated attacker may trigger this vulnerabil...
CVE-2025-59365MEDIUM6.9A stack buffer overflow vulnerability has been identified in certain router models. An authenticated attacker may trigge...
CVE-2025-13452MEDIUM4.3The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to Missing Au...
CVE-2025-13414MEDIUM5.3The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to unauthorized data export due to a missing...
CVE-2025-13405MEDIUM5.3The Ace Post Type Builder plugin for WordPress is vulnerable to unauthorized custom taxonomy deletion due to missing aut...
CVE-2025-13404MEDIUM5.3The atec Duplicate Page & Post plugin for WordPress is vulnerable to unauthorized post duplication due to missing author...
CVE-2025-13389MEDIUM5.3The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to unauthoriz...
CVE-2025-13386MEDIUM5.3The Social Images Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2025-13385MEDIUM4.9The Bookme – Free Online Appointment Booking and Scheduling Plugin for WordPress is vulnerable to time-based SQL Injecti...
CVE-2025-13383MEDIUM6.1The Job Board by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, an...
CVE-2025-13382MEDIUM4.3The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, ...
CVE-2025-13380MEDIUM6.5The AI Engine for WordPress: ChatGPT, GPT Content Generator plugin for WordPress is vulnerable to Arbitrary File Read in...
CVE-2025-13370MEDIUM4.9The ProjectList plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up...
CVE-2025-13311MEDIUM4.4The Just Highlight plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Highlight Color' setting i...
CVE-2025-12645MEDIUM6.4The Inline frame – Iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedsite' shortcod...
CVE-2025-12634MEDIUM4.3The Refund Request for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a miss...
CVE-2025-12587MEDIUM4.3The Peer Publish plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2025-12586MEDIUM4.3The Conditional Maintenance Mode for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v...
CVE-2025-12525MEDIUM5.3The Locker Content plugin for WordPress is vulnerable to Sensitive Information Exposure in version 1.0.0 via the 'locker...
CVE-2025-12043MEDIUM5.3The Autochat Automatic Conversation plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2025-12040MEDIUM6.5The Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up t...
CVE-2025-12032MEDIUM4.4The Zweb Social Mobile – Ứng Dụng Nút Gọi Mobile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2025-12025MEDIUM4.4The YouTube Subscribe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio...
CVE-2025-13643MEDIUM6.5A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are bein...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now