2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-5454MEDIUM6.7An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to pote...
CVE-2025-5452MEDIUM6.6A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applicat...
CVE-2025-4645MEDIUM6.7An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vuln...
CVE-2025-11237MEDIUM5.3The Make Email Customizer for WooCommerce WordPress plugin through 1.0.6 lacks proper authorization checks and option va...
CVE-2025-12880MEDIUM5.4The Progress Bar Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File upl...
CVE-2025-12754MEDIUM6.4The Geopost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter of the 'geopost...
CVE-2025-12753MEDIUM6.4The Chart Expert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pmzez_chart' shortcode in al...
CVE-2025-12711MEDIUM6.4The Share to Google Classroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the share_to_google ...
CVE-2025-12672MEDIUM6.4The Flickr Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'div_height' parameter of the ...
CVE-2025-12671MEDIUM6.4The WP-Iconics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_icon...
CVE-2025-12668MEDIUM6.4The WP Count Down Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the...
CVE-2025-12667MEDIUM6.4The GitHub Gist Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of th...
CVE-2025-12665MEDIUM4.3The Ninja Countdown | Fastest Countdown Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a...
CVE-2025-12663MEDIUM6.4The Jeba Cute forkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' parameter in the '...
CVE-2025-12662MEDIUM6.4The Coon Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter in the...
CVE-2025-12658MEDIUM6.4The Preload Current Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'complete' paramete...
CVE-2025-12652MEDIUM6.4The Ungapped Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prefillvalues' parameter...
CVE-2025-12651MEDIUM6.4The Live Photos on WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_src', 'img...
CVE-2025-12644MEDIUM6.4The Nonaki – Drag and Drop Email Template builder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2025-12632MEDIUM5.5The RandomQuotr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ...
CVE-2025-12631MEDIUM4.4The Squirrels Auto Inventory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all...
CVE-2025-12590MEDIUM6.1The YSlider plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versi...
CVE-2025-12589MEDIUM6.1The WP-Walla plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all vers...
CVE-2025-12588MEDIUM4.3The USB Qr Code Scanner For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
CVE-2025-12538MEDIUM4.4The Fleet Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now