2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66066 | MEDIUM | 6.5 | 0.2% | Nov 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo Ex... |
| CVE-2025-66065 | MEDIUM | 6.5 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in Jegstudio Gutenverse gutenverse allows Exploiting Incorrectly Configured Access C... |
| CVE-2025-66064 | MEDIUM | 4.3 | 0.1% | Nov 21, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Giveaways and Contests by RafflePress rafflepress allows ... |
| CVE-2025-66063 | MEDIUM | 5.4 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in jgwhite33 WP Google Review Slider wp-google-places-review-slider allows Exploitin... |
| CVE-2025-66062 | LOW | 3.4 | 0.2% | Nov 21, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Frank Goossens WP YouTube Lyte wp-youtube-lyte allo... |
| CVE-2025-66061 | MEDIUM | 4.3 | 0.1% | Nov 21, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting ... |
| CVE-2025-66060 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Explo... |
| CVE-2025-66059 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Craig Hewitt Seriously Simpl... |
| CVE-2025-66057 | MEDIUM | 6.5 | 0.2% | Nov 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Pa... |
| CVE-2025-66056 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Uncanny Owl Uncanny Automato... |
| CVE-2025-66055 | HIGH | 7.2 | 0.4% | Nov 21, 2025 | Deserialization of Untrusted Data vulnerability in Icegram Email Subscribers & Newsletters email-subscribers allows Obje... |
| CVE-2025-66053 | MEDIUM | 6.5 | 0.2% | Nov 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold enfo... |
| CVE-2025-12935 | MEDIUM | 6.4 | 0.3% | Nov 21, 2025 | The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin f... |
| CVE-2025-10054 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification ... |
| CVE-2025-10039 | MEDIUM | 4.3 | 0.3% | Nov 21, 2025 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Insecure Direct Object Ref... |
| CVE-2025-40211 | — | — | 0.2% | Nov 21, 2025 | In the Linux kernel, the following vulnerability has been resolved: ACPI: video: Fix use-after-free in acpi_video_switc... |
| CVE-2025-40210 | HIGH | 7.5 | 0.2% | Nov 21, 2025 | In the Linux kernel, the following vulnerability has been resolved: Revert "NFSD: Remove the cap on number of operation... |
| CVE-2025-40209 | — | — | 0.2% | Nov 21, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix memory leak of qgroup_list in btrfs_add_... |
| CVE-2025-13138 | HIGH | 7.5 | 1.4% | Nov 21, 2025 | The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'columns_search' parameter of the selec... |
| CVE-2025-12964 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The Magical Products Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mpdpr_title_tag'... |
| CVE-2025-12750 | MEDIUM | 4.9 | 0.3% | Nov 21, 2025 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to SQL Injection via the ... |
| CVE-2025-12160 | HIGH | 7.2 | 0.2% | Nov 21, 2025 | The Simple User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpr_admin_msg' p... |
| CVE-2025-12066 | MEDIUM | 4.4 | 0.2% | Nov 21, 2025 | The WP Delete Post Copies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve... |
| CVE-2025-13156 | HIGH | 8.8 | 0.6% | Nov 21, 2025 | The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to mi... |
| CVE-2025-13149 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin fo... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now