2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-30186 | MEDIUM | 5.4 | 0.2% | Nov 27, 2025 | Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintend... |
| CVE-2025-13381 | MEDIUM | 5.3 | 0.2% | Nov 27, 2025 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due t... |
| CVE-2025-13378 | MEDIUM | 6.5 | 0.2% | Nov 27, 2025 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forge... |
| CVE-2025-12584 | MEDIUM | 5.3 | 0.2% | Nov 27, 2025 | The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inc... |
| CVE-2025-13536 | HIGH | 8.8 | 0.5% | Nov 27, 2025 | The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valida... |
| CVE-2025-13441 | MEDIUM | 5.3 | 0.2% | Nov 27, 2025 | The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versio... |
| CVE-2025-13157 | MEDIUM | 5.3 | 0.2% | Nov 27, 2025 | The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions... |
| CVE-2025-13525 | MEDIUM | 6.1 | 0.2% | Nov 27, 2025 | The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order_by' parameter i... |
| CVE-2025-13143 | MEDIUM | 4.3 | 0.1% | Nov 27, 2025 | The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Cross-Site Request Forgery i... |
| CVE-2025-12185 | MEDIUM | 4.4 | 0.2% | Nov 27, 2025 | The StaffList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to... |
| CVE-2025-12123 | MEDIUM | 6.1 | 0.2% | Nov 27, 2025 | The Customer Reviews Collector for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ... |
| CVE-2025-7820 | HIGH | 7.5 | 0.3% | Nov 27, 2025 | The SKT PayPal for WooCommerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including... |
| CVE-2025-3784 | MEDIUM | 5.5 | 0.1% | Nov 27, 2025 | Cleartext Storage of Sensitive Information Vulnerability in GX Works2 all versions allows an attacker to disclose creden... |
| CVE-2025-13680 | HIGH | 8.8 | 0.2% | Nov 27, 2025 | The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This ... |
| CVE-2025-13675 | CRITICAL | 9.8 | 0.3% | Nov 27, 2025 | The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This ... |
| CVE-2025-13540 | CRITICAL | 9.8 | 0.3% | Nov 27, 2025 | The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.... |
| CVE-2025-13539 | CRITICAL | 9.8 | 0.4% | Nov 27, 2025 | The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,... |
| CVE-2025-13538 | CRITICAL | 9.8 | 0.3% | Nov 27, 2025 | The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0... |
| CVE-2025-12758 | HIGH | 7.7 | 0.5% | Nov 27, 2025 | Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Spe... |
| CVE-2025-12151 | MEDIUM | 6.4 | 0.2% | Nov 27, 2025 | The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'portfolio_name' parameter in... |
| CVE-2025-66314 | HIGH | 7.5 | 0.2% | Nov 27, 2025 | Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Proper... |
| CVE-2025-34351 | — | — | — | Nov 27, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. At the request of the MITRE ... |
| CVE-2025-13762 | MEDIUM | 4.8 | 0.1% | Nov 27, 2025 | Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial... |
| CVE-2025-12713 | MEDIUM | 6.4 | 0.2% | Nov 27, 2025 | The Soundslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the soundslides shortcode in all v... |
| CVE-2025-12712 | MEDIUM | 6.4 | 0.2% | Nov 27, 2025 | The Shouty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shouty shortcode in all versions up... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now