2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66128 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in Brevo Sendinblue for WooCommerce woocommerce-sendinblue-newsletter-subscription a... |
| CVE-2025-66127 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in g5theme Essential Real Estate essential-real-estate allows Exploiting Incorrectly... |
| CVE-2025-66126 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in wowpress.host Fix Media Library wow-media-library-fix... |
| CVE-2025-66125 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Nitesh Ultimate Auction ultimate-auction allows Retr... |
| CVE-2025-66124 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in ZEEN101 Leaky Paywall leaky-paywall allows Exploiting Incorrectly Configured Acce... |
| CVE-2025-66122 | MEDIUM | 5.3 | 0.3% | Dec 16, 2025 | Missing Authorization vulnerability in Design Stylish Price List stylish-price-list allows Exploiting Incorrectly Config... |
| CVE-2025-66121 | MEDIUM | 5.3 | 0.3% | Dec 16, 2025 | Missing Authorization vulnerability in SiteGround SiteGround Security sg-security allows Exploiting Incorrectly Configur... |
| CVE-2025-66120 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in CatFolders CatFolders catfolders allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-64639 | MEDIUM | 5.3 | 0.3% | Dec 16, 2025 | Missing Authorization vulnerability in WP Compress WP Compress for MainWP wp-compress-mainwp allows Exploiting Incorrect... |
| CVE-2025-64638 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in OnPay.io OnPay.io for WooCommerce onpay-io-for-woocommerce allows Exploiting Inco... |
| CVE-2025-64635 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in Syed Balkhi Feeds for YouTube feeds-for-youtube allows Exploiting Incorrectly Con... |
| CVE-2025-64634 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in ThemeFusion Avada avada allows Accessing Functionality Not Properly Constrained b... |
| CVE-2025-64633 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in colabrio Norebro Extra no... |
| CVE-2025-64632 | MEDIUM | 5.3 | 0.3% | Dec 16, 2025 | Missing Authorization vulnerability in Auctollo Google XML Sitemaps google-sitemap-generator allows Exploiting Incorrect... |
| CVE-2025-64631 | MEDIUM | 4.9 | 0.3% | Dec 16, 2025 | Missing Authorization vulnerability in WC Lovers WCFM Marketplace wc-multivendor-marketplace allows Exploiting Incorrect... |
| CVE-2025-64630 | MEDIUM | 4.9 | 0.3% | Dec 16, 2025 | Missing Authorization vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Exploiting In... |
| CVE-2025-64253 | MEDIUM | 4.9 | 0.4% | Dec 16, 2025 | Path Traversal: '.../...//' vulnerability in WordPress.org Health Check & Troubleshooting health-check allows Path Trave... |
| CVE-2025-64251 | MEDIUM | 4.9 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in azzaroco Ultimate Learning Pro indeed-learning-pro allows Exploiting Incorrectly ... |
| CVE-2025-64250 | MEDIUM | 4.7 | 0.2% | Dec 16, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wpWax Directorist directorist allows Phishing.This ... |
| CVE-2025-64249 | MEDIUM | 5.3 | 0.3% | Dec 16, 2025 | Missing Authorization vulnerability in WP-EXPERTS.IN Protect WP Admin protect-wp-admin allows Exploiting Incorrectly Con... |
| CVE-2025-64248 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in emarket-design Request a Quote request-a-quote allows Exploiting Incorrectly Conf... |
| CVE-2025-64247 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in edmon.parker Read More & Accordion expand-maker allows Exploiting Incorrectly Con... |
| CVE-2025-64246 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in netopsae Accessibility by AudioEye accessibility-by-audioeye allows Exploiting In... |
| CVE-2025-64245 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in ryanpcmcquen Import external attachments import-external-attachments allows Explo... |
| CVE-2025-64244 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in Codexpert, Inc Restrict Elementor Widgets, Columns and Sections restrict-elemento... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now