2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12452 | MEDIUM | 6.1 | 0.1% | Nov 4, 2025 | The Visit Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missin... |
| CVE-2025-12416 | MEDIUM | 6.1 | 0.1% | Nov 4, 2025 | The Pagerank Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Request Forgery in a... |
| CVE-2025-12415 | MEDIUM | 6.1 | 0.1% | Nov 4, 2025 | The MapMap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. T... |
| CVE-2025-12413 | MEDIUM | 5.4 | 0.1% | Nov 4, 2025 | The Social Media WPCF7 Stop Words plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to... |
| CVE-2025-12412 | MEDIUM | 6.1 | 0.1% | Nov 4, 2025 | The Top Bar Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2025-12410 | MEDIUM | 6.1 | 0.1% | Nov 4, 2025 | The SH Contextual Help plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2025-12403 | MEDIUM | 6.1 | 0.1% | Nov 4, 2025 | The Associados Amazon Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and... |
| CVE-2025-12402 | MEDIUM | 6.1 | 0.1% | Nov 4, 2025 | The LinkedIn Resume plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2025-12400 | MEDIUM | 6.1 | 0.1% | Nov 4, 2025 | The LMB^Box Smileys plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2025-12396 | MEDIUM | 4.4 | 0.2% | Nov 4, 2025 | The clubmember plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t... |
| CVE-2025-12393 | MEDIUM | 4.4 | 0.2% | Nov 4, 2025 | The Free Quotation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions ... |
| CVE-2025-12389 | MEDIUM | 4.3 | 0.2% | Nov 4, 2025 | The Import Export For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2025-12371 | MEDIUM | 4.4 | 0.2% | Nov 4, 2025 | The Nari Accountant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via account settings in all versio... |
| CVE-2025-12369 | MEDIUM | 6.4 | 0.2% | Nov 4, 2025 | The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `geojsonmarker`... |
| CVE-2025-12350 | MEDIUM | 5.3 | 0.2% | Nov 4, 2025 | The DominoKit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax... |
| CVE-2025-12188 | MEDIUM | 4.3 | 0.1% | Nov 4, 2025 | The Posts Navigation Links for Sections and Headings – Free by WP Masters plugin for WordPress is vulnerable to Cross-Si... |
| CVE-2025-12157 | MEDIUM | 5.3 | 0.2% | Nov 4, 2025 | The Simple User Capabilities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca... |
| CVE-2025-12156 | MEDIUM | 4.3 | 0.2% | Nov 4, 2025 | The Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One plugin for WordPress is vulnerable to un... |
| CVE-2025-12065 | MEDIUM | 4.4 | 0.2% | Nov 4, 2025 | The WP Carticon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carticon_js_script' parameter... |
| CVE-2025-11812 | MEDIUM | 6.4 | 0.2% | Nov 4, 2025 | The Reuse Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'reuse_builder_single_post_t... |
| CVE-2025-11758 | MEDIUM | 6.5 | 0.2% | Nov 4, 2025 | The All in One Time Clock Lite plugin for WordPress is vulnerable to unauthorized access due to a missing authorization ... |
| CVE-2025-11753 | MEDIUM | 4.4 | 0.2% | Nov 4, 2025 | The Bootstrap Multi-language Responsive Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2025-47370 | MEDIUM | 6.5 | 0.1% | Nov 4, 2025 | Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan. |
| CVE-2025-47362 | MEDIUM | 6.1 | 0.1% | Nov 4, 2025 | Information disclosure while processing message from client with invalid payload. |
| CVE-2025-27064 | MEDIUM | 6.1 | 0.1% | Nov 4, 2025 | Information disclosure while registering commands from clients with diag through diagHal. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now