2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64285 | MEDIUM | 5.4 | 0.2% | Oct 29, 2025 | Missing Authorization vulnerability in Premmerce Premmerce Wholesale Pricing for WooCommerce premmerce-woocommerce-whole... |
| CVE-2025-64283 | MEDIUM | 6.5 | 0.2% | Oct 29, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Rometheme RTMKit rometheme-for-elementor allows Exploi... |
| CVE-2025-64234 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | Missing Authorization vulnerability in Evergreen Content Poster Evergreen Content Poster evergreen-content-poster allows... |
| CVE-2025-64229 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting In... |
| CVE-2025-64228 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in FantasticPlugins SUMO Affili... |
| CVE-2025-64226 | MEDIUM | 4.3 | 0.1% | Oct 29, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in colabrio Stockie Extra stockie-extra allows Cross Site Request Forger... |
| CVE-2025-64220 | MEDIUM | 6.5 | 0.2% | Oct 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ReyCommerce Rey Co... |
| CVE-2025-64219 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | Missing Authorization vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Exploiting In... |
| CVE-2025-64212 | MEDIUM | 5.4 | 0.2% | Oct 29, 2025 | Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro... |
| CVE-2025-64211 | MEDIUM | 5.3 | 0.2% | Oct 29, 2025 | Missing Authorization vulnerability in StylemixThemes Masterstudy Elementor Widgets masterstudy-elementor-widgets allows... |
| CVE-2025-64210 | MEDIUM | 5.4 | 0.2% | Oct 29, 2025 | Missing Authorization vulnerability in StylemixThemes Masterstudy Elementor Widgets masterstudy-elementor-widgets allows... |
| CVE-2025-64208 | MEDIUM | 6.5 | 0.2% | Oct 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TieLabs Jannah - E... |
| CVE-2025-64204 | MEDIUM | 6.5 | 0.2% | Oct 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeSphere SmartM... |
| CVE-2025-64202 | MEDIUM | 6.5 | 0.2% | Oct 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TieLabs Sahifa sah... |
| CVE-2025-64201 | MEDIUM | 4.3 | 0.1% | Oct 29, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in blubrry PowerPress Podcasting powerpress allows Cross Site Request Fo... |
| CVE-2025-64200 | MEDIUM | 5.9 | 0.2% | Oct 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Email T... |
| CVE-2025-64199 | MEDIUM | 5.3 | 0.2% | Oct 29, 2025 | Missing Authorization vulnerability in WpEstate wpresidence wpresidence allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-64197 | MEDIUM | 6.5 | 0.2% | Oct 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sizam Rehub rehub-... |
| CVE-2025-64194 | MEDIUM | 6.5 | 0.2% | Oct 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress Eduma ed... |
| CVE-2025-58939 | MEDIUM | 4.3 | 0.1% | Oct 29, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in highwarden Super Store Finder superstorefinder-wp allows Cross Site R... |
| CVE-2025-58711 | MEDIUM | 5.3 | 0.2% | Oct 29, 2025 | Missing Authorization vulnerability in solwin Blog Designer PRO blog-designer-pro allows Accessing Functionality Not Pro... |
| CVE-2025-12058 | MEDIUM | 5.9 | 0.2% | Oct 29, 2025 | The Keras.Model.load_model method, including when executed with the intended security mitigation safe_mode=True, is vuln... |
| CVE-2025-9544 | MEDIUM | 6.5 | 0.2% | Oct 29, 2025 | The Doppler Forms WordPress plugin through 2.5.1 registers an AJAX action install_extension without verifying user capab... |
| CVE-2025-49042 | MEDIUM | 5.9 | 0.2% | Oct 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooComm... |
| CVE-2025-11705 | MEDIUM | 6.5 | 0.6% | Oct 29, 2025 | The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all vers... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now