2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-58853HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Popping Sidebars and Widgets Light popping-sidebars-and-wid...
CVE-2025-58852HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Mark O'Donnell MSTW League Manager mstw-league-manager allows Stored ...
CVE-2025-58849HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Deepak S Hide Real Download Path hide-real-download-path allows Store...
CVE-2025-58848HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in aakash1911 WP likes wp-likes allows Reflected XSS.This issue affects ...
CVE-2025-58847HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Yaidier WN Flipbox Pro wn-flipbox-pro allows Reflected XSS.This issue...
CVE-2025-58846HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Dejan Markovic WordPress Buffer – HYPESocial. Social Media Auto Post,...
CVE-2025-58845HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in ChrisHurst Bulk Watermark bulk-watermark allows Reflected XSS.This is...
CVE-2025-58844HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Subhash Kumar Database to Excel database-to-excel allows Stored XSS.T...
CVE-2025-58843HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in David Merinas Auto Last Youtube Video auto-last-youtube-video allows ...
CVE-2025-58839HIGH7.2Deserialization of Untrusted Data vulnerability in aThemeArt Translations eDS Responsive Menu eds-responsive-menu allows...
CVE-2025-58833HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in INVELITY Invelity MyGLS connect invelity-mygls-connect allows Object ...
CVE-2025-58815HIGH7.2Deserialization of Untrusted Data vulnerability in Rubel Miah Aitasi Coming Soon aitasi-coming-soon allows Object Inject...
CVE-2025-58809HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Nick Ciske To Lead For Salesforce salesforce-wordpress-to-lead allows...
CVE-2025-58807HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Dsingh Purge Varnish Cache purge-varnish allows Stored XSS.This issue...
CVE-2025-58806HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Tom Longridge WordPress Error Monitoring by Bugsnag bugsnag allows St...
CVE-2025-58789HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle WP Full ...
CVE-2025-58788HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal License...
CVE-2025-10011HIGH8.8A weakness has been identified in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the fil...
CVE-2025-58400HIGH8.4RATOC RAID Monitoring Manager for Windows provided by RATOC Systems, Inc. registers a Windows service with an unquoted f...
CVE-2025-55671HIGH8.5Uncontrolled search path element issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited...
CVE-2025-9990HIGH8.1The WordPress Helpdesk Integration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and...
CVE-2025-58362HIGH7.5Hono is a Web application framework that provides support for any JavaScript runtime. Versions 4.8.0 through 4.9.5 conta...
CVE-2025-55242HIGH7.5Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose informati...
CVE-2025-55238HIGH7.5Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability
CVE-2025-58353HIGH8.2Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All version...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now