2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12661 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The Pollcaster Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter in... |
| CVE-2025-12660 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The Padlet Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'key' parameter in the 'w... |
| CVE-2025-12170 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | The Checkbox plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'w... |
| CVE-2025-12086 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in... |
| CVE-2025-11885 | MEDIUM | 6.1 | 0.2% | Nov 21, 2025 | The EchBay Admin Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_ebnonce' parame... |
| CVE-2025-11815 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthoriz... |
| CVE-2025-11802 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The Bulma Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' shortcode attribut... |
| CVE-2025-11801 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The AudioTube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' shortcode attribute of... |
| CVE-2025-11800 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The Surbma | MiniCRM Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode ... |
| CVE-2025-11799 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The Affiliate AI Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'asin' shortcode attribu... |
| CVE-2025-11773 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | The Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO plugin for WordPress is vulnerable to un... |
| CVE-2025-11771 | MEDIUM | 5.3 | 0.3% | Nov 21, 2025 | The Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO plugin for WordPress is vulnerable to un... |
| CVE-2025-11770 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The BrightTALK WordPress Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'format' sh... |
| CVE-2025-11768 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The Islamic Phrases plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phrases' shortcode attrib... |
| CVE-2025-11767 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The Tips Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tip' shortcode in all vers... |
| CVE-2025-11765 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The Stock Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'image_height' and 'image_widt... |
| CVE-2025-11764 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The Shortcodes Bootstrap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' parameter in t... |
| CVE-2025-11763 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The Display Pages Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'column_count' par... |
| CVE-2025-11003 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthoriz... |
| CVE-2025-10938 | MEDIUM | 6.5 | 0.2% | Nov 21, 2025 | The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi... |
| CVE-2025-62687 | MEDIUM | 6.9 | 0.1% | Nov 21, 2025 | Cross-site request forgery vulnerability exists in LogStare Collector. If a user views a crafted page while logged, unin... |
| CVE-2025-62189 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | LogStare Collector contains an incorrect authorization vulnerability in UserRegistration. If exploited, a non-administra... |
| CVE-2025-61949 | MEDIUM | 5.4 | 0.1% | Nov 21, 2025 | LogStare Collector contains a stored cross-site scripting vulnerability in UserManagement. If crafted user information i... |
| CVE-2025-9825 | MEDIUM | 6.5 | 0.3% | Nov 21, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 ... |
| CVE-2025-13499 | MEDIUM | 5.5 | 0.1% | Nov 21, 2025 | Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now