2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-30186MEDIUM5.4Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintend...
CVE-2025-13381MEDIUM5.3The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due t...
CVE-2025-13378MEDIUM6.5The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forge...
CVE-2025-12584MEDIUM5.3The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inc...
CVE-2025-13536HIGH8.8The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valida...
CVE-2025-13441MEDIUM5.3The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versio...
CVE-2025-13157MEDIUM5.3The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions...
CVE-2025-13525MEDIUM6.1The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order_by' parameter i...
CVE-2025-13143MEDIUM4.3The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Cross-Site Request Forgery i...
CVE-2025-12185MEDIUM4.4The StaffList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to...
CVE-2025-12123MEDIUM6.1The Customer Reviews Collector for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ...
CVE-2025-7820HIGH7.5The SKT PayPal for WooCommerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including...
CVE-2025-3784MEDIUM5.5Cleartext Storage of Sensitive Information Vulnerability in GX Works2 all versions allows an attacker to disclose creden...
CVE-2025-13680HIGH8.8The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This ...
CVE-2025-13675CRITICAL9.8The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This ...
CVE-2025-13540CRITICAL9.8The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1....
CVE-2025-13539CRITICAL9.8The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,...
CVE-2025-13538CRITICAL9.8The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0...
CVE-2025-12758HIGH7.7Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Spe...
CVE-2025-12151MEDIUM6.4The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'portfolio_name' parameter in...
CVE-2025-66314HIGH7.5Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Proper...
CVE-2025-34351Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. At the request of the MITRE ...
CVE-2025-13762MEDIUM4.8Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial...
CVE-2025-12713MEDIUM6.4The Soundslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the soundslides shortcode in all v...
CVE-2025-12712MEDIUM6.4The Shouty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shouty shortcode in all versions up...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now