2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13390CRITICAL9.8The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1...
CVE-2025-13359MEDIUM6.5The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL...
CVE-2025-13354MEDIUM4.3The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization ...
CVE-2025-13342CRITICAL9.8The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress ...
CVE-2025-13109MEDIUM4.3The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Re...
CVE-2025-12887MEDIUM5.4The Post SMTP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.1. Th...
CVE-2025-12358MEDIUM4.3The ShopEngine Elementor WooCommerce Builder Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in a...
CVE-2025-39665MEDIUM5.3User enumeration in Nagvis' Checkmk MultisiteAuth before version 1.9.48 allows an unauthenticated attacker to enumerate ...
CVE-2025-13947HIGH7.4A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal an...
CVE-2025-29864MEDIUM6.2Protection Mechanism Failure vulnerability in ESTsoft ALZip on Windows allows SmartScreen bypass.This issue affects ALZi...
CVE-2025-13472MEDIUM5.3A fix was made in BlazeMeter Jenkins Plugin version 4.27 to allow users only with certain permissions to see the list of...
CVE-2025-12744HIGH8.8A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from a...
CVE-2025-13946MEDIUM5.5MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service
CVE-2025-13945MEDIUM5.5HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
CVE-2025-13486CRITICAL9.8The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 thr...
CVE-2025-12954LOW2.7The Timetable and Event Schedule by MotoPress WordPress plugin before 2.4.16 does not verify a user has access to a spec...
CVE-2025-13495MEDIUM4.9The FluentCart plugin for WordPress is vulnerable to SQL Injection via the 'groupKey' parameter in all versions up to, a...
CVE-2025-12585MEDIUM5.3The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio...
CVE-2025-10304MEDIUM5.3The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to u...
CVE-2025-13646MEDIUM6.6The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio...
CVE-2025-13645HIGH7.2The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val...
CVE-2025-13448MEDIUM6.4The CSSIgniter Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' shortcode ...
CVE-2025-65955MEDIUM6.1ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9....
CVE-2025-66476HIGH7.8Vim is an open source, command line text editor. Prior to version 9.1.1947, an uncontrolled search path vulnerability on...
CVE-2025-55181MEDIUM5.3Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuic...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now