2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52738 | MEDIUM | 6.5 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in Wikimedia Foundation Wikipedia Preview wikipedia-preview allows Exploiting Incorr... |
| CVE-2025-49961 | MEDIUM | 6.5 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in Breeze Team Breeze Checkout breeze-checkout allows Exploiting Incorrectly Configu... |
| CVE-2025-49960 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leadbi LeadBI Plug... |
| CVE-2025-49952 | MEDIUM | 6.5 | 0.4% | Oct 22, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in favethemes Houzez houzez allows Exploiting Incorrectly... |
| CVE-2025-49949 | MEDIUM | 5.4 | 0.2% | Oct 22, 2025 | Missing Authorization vulnerability in templazee Templazee templazee allows Exploiting Incorrectly Configured Access Con... |
| CVE-2025-49940 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Fusion... |
| CVE-2025-49939 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElem... |
| CVE-2025-49938 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngi... |
| CVE-2025-49937 | MEDIUM | 4.3 | 0.2% | Oct 22, 2025 | Missing Authorization vulnerability in Syed Balkhi Smash Balloon Social Post Feed custom-facebook-feed allows Exploiting... |
| CVE-2025-49936 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xtemos WoodMart wo... |
| CVE-2025-49934 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBloc... |
| CVE-2025-49933 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlog... |
| CVE-2025-49932 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlog... |
| CVE-2025-49929 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Blocks Ul... |
| CVE-2025-49928 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetWooB... |
| CVE-2025-49927 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetWooB... |
| CVE-2025-49923 | MEDIUM | 5.9 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Serio... |
| CVE-2025-49922 | MEDIUM | 4.3 | 0.2% | Oct 22, 2025 | Missing Authorization vulnerability in etruel WPeMatico RSS Feed Fetcher wpematico allows Exploiting Incorrectly Configu... |
| CVE-2025-49920 | MEDIUM | 5.4 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in accessiBe Web Accessibility By accessiBe accessibe allows Exploiting Incorrectly ... |
| CVE-2025-49917 | MEDIUM | 4.4 | 0.2% | Oct 22, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Icegram Icegram Express Pro email-subscribers-premium allows Server ... |
| CVE-2025-49913 | MEDIUM | 5.3 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in CoSchedule CoSchedule coschedule-by-todaymade allows Exploiting Incorrectly Confi... |
| CVE-2025-49912 | MEDIUM | 5.9 | 0.3% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nks Email Subscrip... |
| CVE-2025-49908 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPClever WPC Count... |
| CVE-2025-49907 | MEDIUM | 4.3 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Exploiting Incorre... |
| CVE-2025-49906 | MEDIUM | 5.3 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in StellarWP WPComplete wpcomplete allows Accessing Functionality Not Properly Const... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now