2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-11745MEDIUM6.4The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom ...
CVE-2025-58337MEDIUM5.4An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, ...
CVE-2025-12469MEDIUM4.3The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulne...
CVE-2025-12468MEDIUM5.3The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulne...
CVE-2025-12192MEDIUM5.3The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15....
CVE-2025-11987MEDIUM6.4The Visual Link Preview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's visual-link-p...
CVE-2025-11820MEDIUM6.4The Graphina – Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multipl...
CVE-2025-12677MEDIUM5.3The KiotViet Sync plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2025-12676MEDIUM5.3The KiotViet Sync plugin for WordPress is vulnerable to authorizarion bypass in all versions up to, and including, 1.8.5...
CVE-2025-12675MEDIUM4.3The KiotViet Sync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch...
CVE-2025-12388MEDIUM6.4The B Carousel Block – Responsive Image and Content Carousel plugin for WordPress is vulnerable to Server-Side Request F...
CVE-2025-11917MEDIUM6.4The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, ...
CVE-2025-11373MEDIUM4.3The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel...
CVE-2025-6027MEDIUM6.3The Ace User Management WordPress plugin through 2.0.3 does not properly validate that a password reset token is associa...
CVE-2025-21078MEDIUM6.5Use of insufficiently random value of secretKey in Smart Switch prior to version 3.7.68.6 allows adjacent attackers to a...
CVE-2025-21076MEDIUM5.5Improper handling of insufficient permissions or privileges in Samsung Account prior to version 15.5.00.18 allows local ...
CVE-2025-21073MEDIUM4.1Insecure default configuration in USB connection mode prior to SMR Nov-2025 Release 1 allows privileged physical attacke...
CVE-2025-21071MEDIUM4.4Out-of-bounds write in handling opcode in fingerprint trustlet prior to SMR Nov-2025 Release 1 allows local privileged a...
CVE-2025-11072MEDIUM5.3The MelAbu WP Download Counter Button WordPress plugin through 1.8.6.7 does not validate the path of files to be downloa...
CVE-2025-10873MEDIUM5.3The ElementInvader Addons for Elementor WordPress plugin before 1.4.1 allows unauthenticated user to send arbitrary e-ma...
CVE-2025-10567MEDIUM6.3The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its check...
CVE-2025-11162MEDIUM6.4The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2025-12580MEDIUM6.1The SMS for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in ...
CVE-2025-11835MEDIUM5.3The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres...
CVE-2025-8871MEDIUM5.6The Everest Forms (Pro) plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now