2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13090 | MEDIUM | 4.9 | 0.3% | Dec 2, 2025 | The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up t... |
| CVE-2025-41744 | CRITICAL | 9.1 | 0.4% | Dec 2, 2025 | Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to acce... |
| CVE-2025-41743 | MEDIUM | 4 | 0.1% | Dec 2, 2025 | Insufficient encryption strength in Sprecher Automation SPRECON-E-C, SPRECON-E-P, and SPRECON-E-T3 allows a local unpriv... |
| CVE-2025-41742 | CRITICAL | 9.8 | 0.4% | Dec 2, 2025 | Sprecher Automations SPRECON-E-C, SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker ... |
| CVE-2025-13353 | MEDIUM | 5.5 | 0.1% | Dec 2, 2025 | In gokey versions <0.2.0, a flaw in the seed decryption logic resulted in passwords incorrectly being derived solely f... |
| CVE-2025-13873 | MEDIUM | 5.4 | 0.2% | Dec 2, 2025 | Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application a... |
| CVE-2025-13872 | CRITICAL | 9.1 | 0.3% | Dec 2, 2025 | Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-b... |
| CVE-2025-13871 | HIGH | 8.8 | 0.2% | Dec 2, 2025 | Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to ... |
| CVE-2025-13870 | MEDIUM | 4.3 | 0.2% | Dec 2, 2025 | Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files ... |
| CVE-2025-13724 | HIGH | 7.5 | 0.3% | Dec 2, 2025 | The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to time-based blind SQL Injection via the... |
| CVE-2025-13534 | HIGH | 8.8 | 0.2% | Dec 2, 2025 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Privilege Escalation in al... |
| CVE-2025-13516 | HIGH | 8.1 | 0.9% | Dec 2, 2025 | The SureMail – SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestricted Upload of File with Dangerous Type... |
| CVE-2025-10543 | MEDIUM | 5.3 | 0.2% | Dec 2, 2025 | In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library,... |
| CVE-2025-13696 | MEDIUM | 5.3 | 0.3% | Dec 2, 2025 | The Zigaform plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.6.... |
| CVE-2025-11726 | MEDIUM | 4.3 | 0.3% | Dec 2, 2025 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions ... |
| CVE-2025-10971 | HIGH | 8.8 | 0.1% | Dec 2, 2025 | Insecure Storage of Sensitive Information vulnerability in MeetMe on iOS, Android allows Retrieve Embedded Sensitive Dat... |
| CVE-2025-13685 | MEDIUM | 4.3 | 0.1% | Dec 2, 2025 | The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2025-13140 | MEDIUM | 4.3 | 0.1% | Dec 2, 2025 | The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all... |
| CVE-2025-13007 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | The WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets plugin for WordPress is vulnerable to Stored Cr... |
| CVE-2025-12483 | MEDIUM | 6.5 | 0.2% | Dec 2, 2025 | The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'que... |
| CVE-2025-13001 | MEDIUM | 4.1 | 0.2% | Dec 2, 2025 | The donation WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, a... |
| CVE-2025-13000 | HIGH | 7.7 | 0.3% | Dec 2, 2025 | The db-access WordPress plugin through 0.8.7 does not have authorization in an AJAX action, allowing any authenticated u... |
| CVE-2025-13606 | MEDIUM | 6.5 | 0.1% | Dec 2, 2025 | The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Cross-Site Request Forgery... |
| CVE-2025-13387 | HIGH | 7.2 | 0.3% | Dec 2, 2025 | The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custome... |
| CVE-2025-20792 | MEDIUM | 5.3 | 0.3% | Dec 2, 2025 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now