2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13705 | MEDIUM | 6.4 | 0.2% | Dec 13, 2025 | The Custom Frames plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter of the 'cu... |
| CVE-2025-13403 | MEDIUM | 4.3 | 0.2% | Dec 13, 2025 | The Employee Spotlight – Team Member Showcase & Meet the Team Plugin for WordPress is vulnerable to unauthorized trackin... |
| CVE-2025-13094 | HIGH | 8.8 | 0.4% | Dec 13, 2025 | The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid... |
| CVE-2025-13093 | MEDIUM | 5.3 | 0.2% | Dec 13, 2025 | The Devs CRM – Manage tasks, attendance and teams all together plugin for WordPress is vulnerable to unauthorized modifi... |
| CVE-2025-13092 | MEDIUM | 5.3 | 0.2% | Dec 13, 2025 | The Devs CRM – Manage tasks, attendance and teams all together plugin for WordPress is vulnerable to unauthorized access... |
| CVE-2025-13089 | HIGH | 7.5 | 0.3% | Dec 13, 2025 | The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'hide_fields' and the 'attr_search' par... |
| CVE-2025-13077 | HIGH | 7.5 | 0.4% | Dec 13, 2025 | The افزونه پیامک ووکامرس فوق حرفه ای (جدید) payamito sms woocommerce plugin for WordPress is vulnerable to time-based bl... |
| CVE-2025-12512 | MEDIUM | 4.3 | 0.3% | Dec 13, 2025 | The GenerateBlocks plugin for WordPress is vulnerable to information exposure due to missing object-level authorization ... |
| CVE-2025-12362 | MEDIUM | 5.3 | 0.2% | Dec 13, 2025 | The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vulne... |
| CVE-2025-12109 | MEDIUM | 6.4 | 0.2% | Dec 13, 2025 | The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2025-12077 | MEDIUM | 6.1 | 0.2% | Dec 13, 2025 | The WP to LinkedIn Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in ... |
| CVE-2025-12076 | MEDIUM | 6.1 | 0.2% | Dec 13, 2025 | The Social Media Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage param... |
| CVE-2025-11970 | MEDIUM | 4.4 | 0.2% | Dec 13, 2025 | The Emplibot – AI Content Writer with Keyword Research, Infographics, and Linking | SEO Optimized | Fully Automated plug... |
| CVE-2025-11707 | MEDIUM | 5.3 | 0.4% | Dec 13, 2025 | The Login Lockdown & Protection plugin for WordPress is vulnerable to IP Block Bypass in all versions up to, and includi... |
| CVE-2025-11693 | CRITICAL | 9.8 | 2.0% | Dec 13, 2025 | The Export WP Page to Static HTML & PDF plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers... |
| CVE-2025-11376 | MEDIUM | 6.4 | 0.2% | Dec 13, 2025 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_loo... |
| CVE-2025-11164 | MEDIUM | 4.3 | 0.2% | Dec 13, 2025 | The Mavix Education theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability c... |
| CVE-2025-10738 | CRITICAL | 9.8 | 0.4% | Dec 13, 2025 | The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to SQL Injection via the ‘analytic_id’ paramet... |
| CVE-2025-10289 | MEDIUM | 5.9 | 0.2% | Dec 13, 2025 | The Filter & Grids plugin for WordPress is vulnerable to SQL Injection via the 'phrase' parameter in all versions up to,... |
| CVE-2025-0969 | MEDIUM | 6.5 | 0.4% | Dec 13, 2025 | The Brizy – Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and... |
| CVE-2025-13970 | HIGH | 8 | 0.3% | Dec 13, 2025 | OpenPLC_V3 is vulnerable to a cross-site request forgery (CSRF) attack due to the absence of proper CSRF validation. Th... |
| CVE-2025-67749 | MEDIUM | 5.3 | 0.3% | Dec 12, 2025 | PCSX2 is a free and open-source PlayStation 2 (PS2) emulator. In versions 2.5.377 and below, an unchecked offset and siz... |
| CVE-2025-67721 | HIGH | 7.5 | 0.4% | Dec 12, 2025 | Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to Java. In versions... |
| CVE-2025-14585 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | A vulnerability was found in itsourcecode COVID Tracking System 1.0. Affected by this vulnerability is an unknown functi... |
| CVE-2025-14584 | CRITICAL | 9.8 | 0.3% | Dec 12, 2025 | A vulnerability has been found in itsourcecode COVID Tracking System 1.0. Affected is an unknown function of the file /a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now