2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13390 | CRITICAL | 9.8 | 4.7% | Dec 3, 2025 | The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1... |
| CVE-2025-13359 | MEDIUM | 6.5 | 0.3% | Dec 3, 2025 | The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL... |
| CVE-2025-13354 | MEDIUM | 4.3 | 0.2% | Dec 3, 2025 | The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization ... |
| CVE-2025-13342 | CRITICAL | 9.8 | 0.4% | Dec 3, 2025 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress ... |
| CVE-2025-13109 | MEDIUM | 4.3 | 0.2% | Dec 3, 2025 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Re... |
| CVE-2025-12887 | MEDIUM | 5.4 | 0.3% | Dec 3, 2025 | The Post SMTP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.1. Th... |
| CVE-2025-12358 | MEDIUM | 4.3 | 0.1% | Dec 3, 2025 | The ShopEngine Elementor WooCommerce Builder Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in a... |
| CVE-2025-39665 | MEDIUM | 5.3 | 0.2% | Dec 3, 2025 | User enumeration in Nagvis' Checkmk MultisiteAuth before version 1.9.48 allows an unauthenticated attacker to enumerate ... |
| CVE-2025-13947 | HIGH | 7.4 | 0.3% | Dec 3, 2025 | A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal an... |
| CVE-2025-29864 | MEDIUM | 6.2 | 0.1% | Dec 3, 2025 | Protection Mechanism Failure vulnerability in ESTsoft ALZip on Windows allows SmartScreen bypass.This issue affects ALZi... |
| CVE-2025-13472 | MEDIUM | 5.3 | 0.2% | Dec 3, 2025 | A fix was made in BlazeMeter Jenkins Plugin version 4.27 to allow users only with certain permissions to see the list of... |
| CVE-2025-12744 | HIGH | 8.8 | 0.6% | Dec 3, 2025 | A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from a... |
| CVE-2025-13946 | MEDIUM | 5.5 | 0.1% | Dec 3, 2025 | MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service |
| CVE-2025-13945 | MEDIUM | 5.5 | 0.1% | Dec 3, 2025 | HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service |
| CVE-2025-13486 | CRITICAL | 9.8 | 73.6% | Dec 3, 2025 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 thr... |
| CVE-2025-12954 | LOW | 2.7 | 0.2% | Dec 3, 2025 | The Timetable and Event Schedule by MotoPress WordPress plugin before 2.4.16 does not verify a user has access to a spec... |
| CVE-2025-13495 | MEDIUM | 4.9 | 0.3% | Dec 3, 2025 | The FluentCart plugin for WordPress is vulnerable to SQL Injection via the 'groupKey' parameter in all versions up to, a... |
| CVE-2025-12585 | MEDIUM | 5.3 | 0.3% | Dec 3, 2025 | The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio... |
| CVE-2025-10304 | MEDIUM | 5.3 | 0.2% | Dec 3, 2025 | The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to u... |
| CVE-2025-13646 | MEDIUM | 6.6 | 0.7% | Dec 3, 2025 | The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio... |
| CVE-2025-13645 | HIGH | 7.2 | 0.9% | Dec 3, 2025 | The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val... |
| CVE-2025-13448 | MEDIUM | 6.4 | 0.2% | Dec 3, 2025 | The CSSIgniter Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' shortcode ... |
| CVE-2025-65955 | MEDIUM | 6.1 | 0.1% | Dec 2, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.... |
| CVE-2025-66476 | HIGH | 7.8 | 0.4% | Dec 2, 2025 | Vim is an open source, command line text editor. Prior to version 9.1.1947, an uncontrolled search path vulnerability on... |
| CVE-2025-55181 | MEDIUM | 5.3 | 0.3% | Dec 2, 2025 | Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuic... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now