2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11745 | MEDIUM | 6.4 | 0.2% | Nov 5, 2025 | The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom ... |
| CVE-2025-58337 | MEDIUM | 5.4 | 0.3% | Nov 5, 2025 | An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, ... |
| CVE-2025-12469 | MEDIUM | 4.3 | 0.2% | Nov 5, 2025 | The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulne... |
| CVE-2025-12468 | MEDIUM | 5.3 | 0.3% | Nov 5, 2025 | The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulne... |
| CVE-2025-12192 | MEDIUM | 5.3 | 0.2% | Nov 5, 2025 | The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.... |
| CVE-2025-11987 | MEDIUM | 6.4 | 0.2% | Nov 5, 2025 | The Visual Link Preview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's visual-link-p... |
| CVE-2025-11820 | MEDIUM | 6.4 | 0.2% | Nov 5, 2025 | The Graphina – Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multipl... |
| CVE-2025-12677 | MEDIUM | 5.3 | 0.2% | Nov 5, 2025 | The KiotViet Sync plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2025-12676 | MEDIUM | 5.3 | 0.3% | Nov 5, 2025 | The KiotViet Sync plugin for WordPress is vulnerable to authorizarion bypass in all versions up to, and including, 1.8.5... |
| CVE-2025-12675 | MEDIUM | 4.3 | 0.2% | Nov 5, 2025 | The KiotViet Sync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch... |
| CVE-2025-12388 | MEDIUM | 6.4 | 0.2% | Nov 5, 2025 | The B Carousel Block – Responsive Image and Content Carousel plugin for WordPress is vulnerable to Server-Side Request F... |
| CVE-2025-11917 | MEDIUM | 6.4 | 0.2% | Nov 5, 2025 | The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, ... |
| CVE-2025-11373 | MEDIUM | 4.3 | 0.2% | Nov 5, 2025 | The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel... |
| CVE-2025-6027 | MEDIUM | 6.3 | 0.2% | Nov 5, 2025 | The Ace User Management WordPress plugin through 2.0.3 does not properly validate that a password reset token is associa... |
| CVE-2025-21078 | MEDIUM | 6.5 | 0.2% | Nov 5, 2025 | Use of insufficiently random value of secretKey in Smart Switch prior to version 3.7.68.6 allows adjacent attackers to a... |
| CVE-2025-21076 | MEDIUM | 5.5 | 0.1% | Nov 5, 2025 | Improper handling of insufficient permissions or privileges in Samsung Account prior to version 15.5.00.18 allows local ... |
| CVE-2025-21073 | MEDIUM | 4.1 | 0.2% | Nov 5, 2025 | Insecure default configuration in USB connection mode prior to SMR Nov-2025 Release 1 allows privileged physical attacke... |
| CVE-2025-21071 | MEDIUM | 4.4 | 0.1% | Nov 5, 2025 | Out-of-bounds write in handling opcode in fingerprint trustlet prior to SMR Nov-2025 Release 1 allows local privileged a... |
| CVE-2025-11072 | MEDIUM | 5.3 | 0.3% | Nov 5, 2025 | The MelAbu WP Download Counter Button WordPress plugin through 1.8.6.7 does not validate the path of files to be downloa... |
| CVE-2025-10873 | MEDIUM | 5.3 | 0.2% | Nov 5, 2025 | The ElementInvader Addons for Elementor WordPress plugin before 1.4.1 allows unauthenticated user to send arbitrary e-ma... |
| CVE-2025-10567 | MEDIUM | 6.3 | 0.2% | Nov 5, 2025 | The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its check... |
| CVE-2025-11162 | MEDIUM | 6.4 | 0.2% | Nov 5, 2025 | The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2025-12580 | MEDIUM | 6.1 | 0.2% | Nov 5, 2025 | The SMS for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in ... |
| CVE-2025-11835 | MEDIUM | 5.3 | 0.2% | Nov 5, 2025 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres... |
| CVE-2025-8871 | MEDIUM | 5.6 | 0.2% | Nov 5, 2025 | The Everest Forms (Pro) plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now