2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13090MEDIUM4.9The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up t...
CVE-2025-41744CRITICAL9.1Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to acce...
CVE-2025-41743MEDIUM4Insufficient encryption strength in Sprecher Automation SPRECON-E-C, SPRECON-E-P, and SPRECON-E-T3 allows a local unpriv...
CVE-2025-41742CRITICAL9.8Sprecher Automations SPRECON-E-C,  SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker ...
CVE-2025-13353MEDIUM5.5In gokey versions <0.2.0, a flaw in the seed decryption logic resulted in passwords incorrectly being derived solely f...
CVE-2025-13873MEDIUM5.4Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application a...
CVE-2025-13872CRITICAL9.1Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-b...
CVE-2025-13871HIGH8.8Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to ...
CVE-2025-13870MEDIUM4.3Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files ...
CVE-2025-13724HIGH7.5The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to time-based blind SQL Injection via the...
CVE-2025-13534HIGH8.8The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Privilege Escalation in al...
CVE-2025-13516HIGH8.1The SureMail – SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestricted Upload of File with Dangerous Type...
CVE-2025-10543MEDIUM5.3In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library,...
CVE-2025-13696MEDIUM5.3The Zigaform plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.6....
CVE-2025-11726MEDIUM4.3The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions ...
CVE-2025-10971HIGH8.8Insecure Storage of Sensitive Information vulnerability in MeetMe on iOS, Android allows Retrieve Embedded Sensitive Dat...
CVE-2025-13685MEDIUM4.3The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2025-13140MEDIUM4.3The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
CVE-2025-13007MEDIUM6.1The WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets plugin for WordPress is vulnerable to Stored Cr...
CVE-2025-12483MEDIUM6.5The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'que...
CVE-2025-13001MEDIUM4.1The donation WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, a...
CVE-2025-13000HIGH7.7The db-access WordPress plugin through 0.8.7 does not have authorization in an AJAX action, allowing any authenticated u...
CVE-2025-13606MEDIUM6.5The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Cross-Site Request Forgery...
CVE-2025-13387HIGH7.2The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custome...
CVE-2025-20792MEDIUM5.3In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now