2025 CVE Vulnerabilities
45,158 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68594 | MEDIUM | 5.3 | 0.3% | Dec 24, 2025 | Missing Authorization vulnerability in Opinion Stage Poll, Survey & Quiz Maker Plugin by Opinion Stage social-polls-by-o... |
| CVE-2025-68593 | MEDIUM | 5.4 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Liton Arefin WP Adminify adminify allows Exploiting Incorrectly Configured Access... |
| CVE-2025-68592 | MEDIUM | 4.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Liton Arefin WP Adminify adminify allows Exploiting Incorrectly Configured Access... |
| CVE-2025-68591 | MEDIUM | 5.4 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Mitchell Bennis Simple File List simple-file-list allows Exploiting Incorrectly C... |
| CVE-2025-68590 | HIGH | 7.6 | 0.3% | Dec 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Integrat... |
| CVE-2025-68589 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in WP Socio WP Telegram Widget and Join Link wptelegram-widget allows Exploiting Inc... |
| CVE-2025-68588 | MEDIUM | 4.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in totalsoft TS Poll poll-wp allows Exploiting Incorrectly Configured Access Control... |
| CVE-2025-68587 | MEDIUM | 4.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Bob Watu Quiz watu allows Exploiting Incorrectly Configured Access Control Securi... |
| CVE-2025-68586 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Gora Tech Cooked cooked allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2025-68585 | LOW | 2.7 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Ben Balter WP Document Revisions wp-document-revisions allows Exploiting Incorrec... |
| CVE-2025-68584 | MEDIUM | 4.3 | 0.1% | Dec 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Constantin Boiangiu Vimeotheque codeflavors-vimeo-video-post-lite all... |
| CVE-2025-68583 | MEDIUM | 4.3 | 0.1% | Dec 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Tikweb Management Fast User Switching fast-user-switching allows Cros... |
| CVE-2025-68582 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Funnelforms Funnelforms Free funnelforms-free allows Exploiting Incorrectly Confi... |
| CVE-2025-68581 | MEDIUM | 5.4 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in YITHEMES YITH Slider for page builders yith-slider-for-page-builders allows Explo... |
| CVE-2025-68580 | MEDIUM | 4.3 | 0.1% | Dec 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in pluginsware Advanced Classifieds & Directory Pro advanced-classifieds... |
| CVE-2025-68579 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in FolioVision FV Simpler SEO fv-all-in-one-seo-pack allows Exploiting Incorrectly C... |
| CVE-2025-68578 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Addonify Addonify addonify-quick-view allows Exploiting Incorrectly Configured Ac... |
| CVE-2025-68577 | MEDIUM | 4.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Virusdie Virusdie virusdie allows Exploiting Incorrectly Configured Access Contro... |
| CVE-2025-68576 | MEDIUM | 4.3 | 0.2% | Dec 24, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Virusdie Virusdie virusdie a... |
| CVE-2025-68575 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Wappointment team Wappointment wappointment allows Exploiting Incorrectly Configu... |
| CVE-2025-68574 | MEDIUM | 5.9 | 0.2% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidcoders WPBaker... |
| CVE-2025-68573 | MEDIUM | 5.4 | 0.1% | Dec 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Simple Keyword to Link simple-keyword-to-link allow... |
| CVE-2025-68572 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Spider Themes BBP Core bbp-core allows Exploiting Incorrectly Configured Access C... |
| CVE-2025-68571 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in SALESmanago SALESmanago & Leadoo salesmanago allows Exploiting Incorrectly Config... |
| CVE-2025-68570 | HIGH | 7.6 | 0.3% | Dec 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Cap... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now