2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12359MEDIUM5.4The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t...
CVE-2025-12174MEDIUM6.5The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to...
CVE-2025-12057CRITICAL9.8The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate ...
CVE-2025-12426HIGH7.5The Quiz Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including...
CVE-2025-12349MEDIUM5.3The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Auth...
CVE-2025-6251MEDIUM6.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via $item['fi...
CVE-2025-65941Rejected reason: Not used
CVE-2025-65940Rejected reason: Not used
CVE-2025-65939Rejected reason: Not used
CVE-2025-65938Rejected reason: Not used
CVE-2025-65937Rejected reason: Not used
CVE-2025-65936Rejected reason: Not used
CVE-2025-65935Rejected reason: Not used
CVE-2025-65934Rejected reason: Not used
CVE-2025-65933Rejected reason: Not used
CVE-2025-13051CRITICAL9.3When the service of ABP and AES is installed in a directory writable by non-administrative users, an attacker can replac...
CVE-2025-12777MEDIUM5.3The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and incl...
CVE-2025-12770MEDIUM5.3The New User Approve plugin for WordPress is vulnerable to unauthorized data disclosure in all versions up to, and inclu...
CVE-2025-12427MEDIUM5.3The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up ...
CVE-2025-13225MEDIUM6Tanium addressed an arbitrary file deletion vulnerability in TanOS.
CVE-2025-12852HIGH8.4DLL Loading vulnerability in NEC Corporation RakurakuMusen Start EX All Verisons allows a attacker to manipulate the PC ...
CVE-2025-65093MEDIUM5.5LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based ...
CVE-2025-65015HIGH7.5joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar...
CVE-2025-65014LOW3.7LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password ...
CVE-2025-65013MEDIUM6.1LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cros...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now