2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8780 | MEDIUM | 6.4 | 0.2% | Dec 13, 2025 | The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Hero ... |
| CVE-2025-8779 | MEDIUM | 6.4 | 0.2% | Dec 13, 2025 | The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2025-8687 | MEDIUM | 6.4 | 0.2% | Dec 13, 2025 | The Enter Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown and Image ... |
| CVE-2025-8617 | MEDIUM | 6.4 | 0.3% | Dec 13, 2025 | The YITH WooCommerce Quick View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yith_... |
| CVE-2025-8199 | MEDIUM | 6.4 | 0.2% | Dec 13, 2025 | The MarqueeAddons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial Marquee... |
| CVE-2025-8195 | MEDIUM | 6.4 | 0.2% | Dec 13, 2025 | The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Co... |
| CVE-2025-7960 | MEDIUM | 6.4 | 0.2% | Dec 13, 2025 | The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing... |
| CVE-2025-7058 | MEDIUM | 6.4 | 0.2% | Dec 13, 2025 | The Kingcabs theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘progressbarLayout’ parameter in a... |
| CVE-2025-67871 | — | — | — | Dec 13, 2025 | Rejected reason: Not used |
| CVE-2025-67870 | — | — | — | Dec 13, 2025 | Rejected reason: Not used |
| CVE-2025-67869 | — | — | — | Dec 13, 2025 | Rejected reason: Not used |
| CVE-2025-67868 | — | — | — | Dec 13, 2025 | Rejected reason: Not used |
| CVE-2025-67867 | — | — | — | Dec 13, 2025 | Rejected reason: Not used |
| CVE-2025-67866 | — | — | — | Dec 13, 2025 | Rejected reason: Not used |
| CVE-2025-67865 | — | — | — | Dec 13, 2025 | Rejected reason: Not used |
| CVE-2025-67864 | — | — | — | Dec 13, 2025 | Rejected reason: Not used |
| CVE-2025-67863 | — | — | — | Dec 13, 2025 | Rejected reason: Not used |
| CVE-2025-36754 | CRITICAL | 9.3 | 0.1% | Dec 13, 2025 | The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication check... |
| CVE-2025-36753 | CRITICAL | 9.8 | 0.3% | Dec 13, 2025 | The SWD debug interface on the Growatt ShineLan-X communication dongle is available by default, allowing an attacker to ... |
| CVE-2025-36752 | CRITICAL | 9.8 | 0.3% | Dec 13, 2025 | Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows si... |
| CVE-2025-36751 | CRITICAL | 9.4 | 0.1% | Dec 13, 2025 | Encryption is missing on the configuration interface for Growatt ShineLan-X and MIC 3300TL-X. This allows an attacker wi... |
| CVE-2025-36750 | MEDIUM | 5.4 | 0.1% | Dec 13, 2025 | ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the Plant Name field. A HTML payload will be di... |
| CVE-2025-36748 | MEDIUM | 5.4 | 0.1% | Dec 13, 2025 | ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the local configuration web server. The JavaScr... |
| CVE-2025-36747 | CRITICAL | 9.8 | 0.3% | Dec 13, 2025 | ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish ... |
| CVE-2025-14620 | CRITICAL | 9.8 | 0.4% | Dec 13, 2025 | A vulnerability was determined in code-projects Student File Management System 1.0. Affected by this issue is some unkno... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now