2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59369 | MEDIUM | 5.9 | 0.4% | Nov 25, 2025 | A SQL injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnera... |
| CVE-2025-59368 | MEDIUM | 6 | 0.4% | Nov 25, 2025 | An integer underflow vulnerability has been identified in Aicloud. An authenticated attacker may trigger this vulnerabil... |
| CVE-2025-59365 | MEDIUM | 6.9 | 0.4% | Nov 25, 2025 | A stack buffer overflow vulnerability has been identified in certain router models. An authenticated attacker may trigge... |
| CVE-2025-13452 | MEDIUM | 4.3 | 0.2% | Nov 25, 2025 | The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to Missing Au... |
| CVE-2025-13414 | MEDIUM | 5.3 | 0.2% | Nov 25, 2025 | The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to unauthorized data export due to a missing... |
| CVE-2025-13405 | MEDIUM | 5.3 | 0.2% | Nov 25, 2025 | The Ace Post Type Builder plugin for WordPress is vulnerable to unauthorized custom taxonomy deletion due to missing aut... |
| CVE-2025-13404 | MEDIUM | 5.3 | 0.2% | Nov 25, 2025 | The atec Duplicate Page & Post plugin for WordPress is vulnerable to unauthorized post duplication due to missing author... |
| CVE-2025-13389 | MEDIUM | 5.3 | 0.2% | Nov 25, 2025 | The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to unauthoriz... |
| CVE-2025-13386 | MEDIUM | 5.3 | 0.2% | Nov 25, 2025 | The Social Images Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi... |
| CVE-2025-13385 | MEDIUM | 4.9 | 0.3% | Nov 25, 2025 | The Bookme – Free Online Appointment Booking and Scheduling Plugin for WordPress is vulnerable to time-based SQL Injecti... |
| CVE-2025-13383 | MEDIUM | 6.1 | 0.2% | Nov 25, 2025 | The Job Board by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, an... |
| CVE-2025-13382 | MEDIUM | 4.3 | 0.2% | Nov 25, 2025 | The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, ... |
| CVE-2025-13380 | MEDIUM | 6.5 | 0.5% | Nov 25, 2025 | The AI Engine for WordPress: ChatGPT, GPT Content Generator plugin for WordPress is vulnerable to Arbitrary File Read in... |
| CVE-2025-13370 | MEDIUM | 4.9 | 0.3% | Nov 25, 2025 | The ProjectList plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up... |
| CVE-2025-13311 | MEDIUM | 4.4 | 0.2% | Nov 25, 2025 | The Just Highlight plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Highlight Color' setting i... |
| CVE-2025-12645 | MEDIUM | 6.4 | 0.2% | Nov 25, 2025 | The Inline frame – Iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedsite' shortcod... |
| CVE-2025-12634 | MEDIUM | 4.3 | 0.2% | Nov 25, 2025 | The Refund Request for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a miss... |
| CVE-2025-12587 | MEDIUM | 4.3 | 0.1% | Nov 25, 2025 | The Peer Publish plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2025-12586 | MEDIUM | 4.3 | 0.1% | Nov 25, 2025 | The Conditional Maintenance Mode for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v... |
| CVE-2025-12525 | MEDIUM | 5.3 | 0.3% | Nov 25, 2025 | The Locker Content plugin for WordPress is vulnerable to Sensitive Information Exposure in version 1.0.0 via the 'locker... |
| CVE-2025-12043 | MEDIUM | 5.3 | 0.2% | Nov 25, 2025 | The Autochat Automatic Conversation plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2025-12040 | MEDIUM | 6.5 | 0.2% | Nov 25, 2025 | The Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up t... |
| CVE-2025-12032 | MEDIUM | 4.4 | 0.2% | Nov 25, 2025 | The Zweb Social Mobile – Ứng Dụng Nút Gọi Mobile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2025-12025 | MEDIUM | 4.4 | 0.2% | Nov 25, 2025 | The YouTube Subscribe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio... |
| CVE-2025-13643 | MEDIUM | 6.5 | 0.2% | Nov 25, 2025 | A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are bein... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now