2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62011 | MEDIUM | 6.5 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem... |
| CVE-2025-60247 | MEDIUM | 6.5 | 0.3% | Nov 6, 2025 | Missing Authorization vulnerability in Bux Bux Woocommerce bux-woocommerce allows Accessing Functionality Not Properly C... |
| CVE-2025-60187 | MEDIUM | 4.8 | 0.2% | Nov 6, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Us... |
| CVE-2025-5803 | MEDIUM | 5.3 | 0.2% | Nov 6, 2025 | Missing Authorization vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking.This issue affects VikB... |
| CVE-2025-59392 | MEDIUM | 6.8 | 0.2% | Nov 6, 2025 | On Elspec G5 devices through 1.2.2.19, a person with physical access to the device can reset the Admin password by inser... |
| CVE-2025-58986 | MEDIUM | 6.5 | 0.2% | Nov 6, 2025 | Missing Authorization vulnerability in ganddser Jock On Air Now (JOAN) joan allows Exploiting Incorrectly Configured Acc... |
| CVE-2025-58595 | MEDIUM | 5.3 | 0.3% | Nov 6, 2025 | Authentication Bypass by Spoofing vulnerability in Saad Iqbal All In One Login change-wp-admin-login allows Identity Spo... |
| CVE-2025-58243 | MEDIUM | 5.3 | 0.2% | Nov 6, 2025 | Missing Authorization vulnerability in Jthemes imEvent imevent allows Accessing Functionality Not Properly Constrained b... |
| CVE-2025-53246 | MEDIUM | 6.5 | 0.3% | Nov 6, 2025 | Missing Authorization vulnerability in Gaurav Aggarwal Backup and Move backup-and-move allows Exploiting Incorrectly Con... |
| CVE-2025-53214 | MEDIUM | 6.5 | 0.2% | Nov 6, 2025 | Missing Authorization vulnerability in sertifier Sertifier Certificate & Badge Maker sertifier-certificates-open-badges ... |
| CVE-2025-49398 | MEDIUM | 6.5 | 0.2% | Nov 6, 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Easy Appointments Easy Ap... |
| CVE-2025-48086 | MEDIUM | 5.5 | 0.2% | Nov 6, 2025 | Deserialization of Untrusted Data vulnerability in wpdreams Ajax Search Lite ajax-search-lite allows Object Injection.Th... |
| CVE-2025-39465 | MEDIUM | 4.3 | 0.2% | Nov 6, 2025 | Missing Authorization vulnerability in flippercode Advanced Google Maps wp-google-map-gold allows Exploiting Incorrectly... |
| CVE-2025-22288 | MEDIUM | 4.1 | 0.3% | Nov 6, 2025 | Path Traversal: '.../...//' vulnerability in WPMU DEV - Your All-in-One WordPress Platform Smush Image Compression and O... |
| CVE-2025-36054 | MEDIUM | 6.1 | 0.2% | Nov 6, 2025 | IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004, 25.0.0 through 25.... |
| CVE-2025-10955 | MEDIUM | 6.1 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad Soft... |
| CVE-2025-11268 | MEDIUM | 4.3 | 0.2% | Nov 6, 2025 | The Strong Testimonials plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and i... |
| CVE-2025-12360 | MEDIUM | 4.3 | 0.2% | Nov 6, 2025 | The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to unauthorized API usage due to... |
| CVE-2025-10259 | MEDIUM | 5.3 | 0.4% | Nov 6, 2025 | Improper Validation of Specified Quantity in Input vulnerability in TCP Communication Function on Mitsubishi Electric Co... |
| CVE-2025-12471 | MEDIUM | 6.1 | 0.2% | Nov 6, 2025 | The Hubbub Lite – Fast, free social sharing and follow buttons plugin for WordPress is vulnerable to Reflected Cross-Sit... |
| CVE-2025-12560 | MEDIUM | 4.3 | 0.2% | Nov 6, 2025 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Server-Side Request Forgery in... |
| CVE-2025-61994 | MEDIUM | 5.4 | 0.1% | Nov 6, 2025 | Cross-site scripting vulnerability exists in GROWI prior to v7.2.10. If a malicious user creates a page containing craft... |
| CVE-2025-12563 | MEDIUM | 4.3 | 0.2% | Nov 6, 2025 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to limited file upload due to an ... |
| CVE-2025-11271 | MEDIUM | 5.3 | 0.3% | Nov 6, 2025 | The Easy Digital Downloads plugin for WordPress is vulnerable to Order Manipulation in all versions up to, and including... |
| CVE-2025-10691 | MEDIUM | 4.3 | 0.1% | Nov 6, 2025 | The Easy Email Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now