2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-64243MEDIUM4.3Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Ac...
CVE-2025-64242MEDIUM4.3Missing Authorization vulnerability in Merv Barrett Easy Property Listings easy-property-listings allows Exploiting Inco...
CVE-2025-64241MEDIUM4.3Missing Authorization vulnerability in Imtiaz Rayhan WP Coupons and Deals wp-coupons-and-deals allows Exploiting Incorre...
CVE-2025-64240MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in freshchat Freshchat freshchat allows Cross Site Request Forgery.This ...
CVE-2025-64239MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Yoav Farhi RTL Tester rtl-tester allows Cross Site Request Forgery.Th...
CVE-2025-64238MEDIUM4.3Missing Authorization vulnerability in NicolasKulka WPS Bidouille wps-bidouille allows Exploiting Incorrectly Configured...
CVE-2025-64237MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Graham Quick Interest Slider quick-interest-slider allows Cross Site ...
CVE-2025-59009MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Astoundify Listify listify allows Cross Site Request Forgery.This iss...
CVE-2025-59001MEDIUM4.3Missing Authorization vulnerability in ThemeNectar Salient Core salient-core allows Exploiting Incorrectly Configured Ac...
CVE-2025-58999MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donation...
CVE-2025-54045MEDIUM4.3Missing Authorization vulnerability in CreativeMindsSolutions CM On Demand Search And Replace cm-on-demand-search-and-re...
CVE-2025-54005MEDIUM4.3Missing Authorization vulnerability in sonalsinha21 SKT Page Builder skt-builder allows Exploiting Incorrectly Configure...
CVE-2025-54004LOW2.7Missing Authorization vulnerability in WC Lovers WCFM – Frontend Manager for WooCommerce wc-frontend-manager allows Expl...
CVE-2025-49300LOW2.7Insertion of Sensitive Information Into Sent Data vulnerability in shinetheme Traveler Option Tree custom-option-tree al...
CVE-2025-13231MEDIUM6.5The Fancy Product Designer plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and ...
CVE-2025-13439MEDIUM5.9The Fancy Product Designer plugin for WordPress is vulnerable to Information Disclosure and PHAR Deserialization in all ...
CVE-2025-11991MEDIUM5.3The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2025-66635HIGH8.6Stack-based buffer overflow vulnerability exists in SEIKO EPSON Web Config. Specially crafted data input by a logged-in ...
CVE-2025-62330MEDIUM5.9HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains acce...
CVE-2025-14252HIGH8.5An Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary me...
CVE-2025-13794MEDIUM4.3The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized modification of data du...
CVE-2025-12809MEDIUM5.3The Dokan Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the...
CVE-2025-66357MEDIUM6.9CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper check for unusual or exceptional conditions. When the...
CVE-2025-61976HIGH8.7CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper check for unusual or exceptional conditions. If a rem...
CVE-2025-59479MEDIUM6.1CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper restriction of rendered UI layers or frames. If a use...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now