2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5454 | MEDIUM | 6.7 | 0.1% | Nov 11, 2025 | An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to pote... |
| CVE-2025-5452 | MEDIUM | 6.6 | 0.3% | Nov 11, 2025 | A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applicat... |
| CVE-2025-4645 | MEDIUM | 6.7 | 0.1% | Nov 11, 2025 | An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vuln... |
| CVE-2025-11237 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Make Email Customizer for WooCommerce WordPress plugin through 1.0.6 lacks proper authorization checks and option va... |
| CVE-2025-12880 | MEDIUM | 5.4 | 0.1% | Nov 11, 2025 | The Progress Bar Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File upl... |
| CVE-2025-12754 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Geopost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter of the 'geopost... |
| CVE-2025-12753 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Chart Expert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pmzez_chart' shortcode in al... |
| CVE-2025-12711 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Share to Google Classroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the share_to_google ... |
| CVE-2025-12672 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Flickr Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'div_height' parameter of the ... |
| CVE-2025-12671 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The WP-Iconics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_icon... |
| CVE-2025-12668 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The WP Count Down Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the... |
| CVE-2025-12667 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The GitHub Gist Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of th... |
| CVE-2025-12665 | MEDIUM | 4.3 | 0.2% | Nov 11, 2025 | The Ninja Countdown | Fastest Countdown Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a... |
| CVE-2025-12663 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Jeba Cute forkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' parameter in the '... |
| CVE-2025-12662 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Coon Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter in the... |
| CVE-2025-12658 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Preload Current Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'complete' paramete... |
| CVE-2025-12652 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Ungapped Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prefillvalues' parameter... |
| CVE-2025-12651 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Live Photos on WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_src', 'img... |
| CVE-2025-12644 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Nonaki – Drag and Drop Email Template builder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2025-12632 | MEDIUM | 5.5 | 0.2% | Nov 11, 2025 | The RandomQuotr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ... |
| CVE-2025-12631 | MEDIUM | 4.4 | 0.2% | Nov 11, 2025 | The Squirrels Auto Inventory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all... |
| CVE-2025-12590 | MEDIUM | 6.1 | 0.1% | Nov 11, 2025 | The YSlider plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versi... |
| CVE-2025-12589 | MEDIUM | 6.1 | 0.1% | Nov 11, 2025 | The WP-Walla plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all vers... |
| CVE-2025-12588 | MEDIUM | 4.3 | 0.1% | Nov 11, 2025 | The USB Qr Code Scanner For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions... |
| CVE-2025-12538 | MEDIUM | 4.4 | 0.2% | Nov 11, 2025 | The Fleet Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now