2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-50011 | MEDIUM | 5.9 | 0.2% | Jun 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Félix Martínez Rec... |
| CVE-2025-50010 | MEDIUM | 5.4 | 0.2% | Jun 20, 2025 | Missing Authorization vulnerability in Zapier Zapier for WordPress zapier allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-50009 | MEDIUM | 5.4 | 0.3% | Jun 20, 2025 | Missing Authorization vulnerability in Climax Themes Kata Plus kata-plus allows Exploiting Incorrectly Configured Access... |
| CVE-2025-50008 | MEDIUM | 5.4 | 0.3% | Jun 20, 2025 | Missing Authorization vulnerability in cscode WooCommerce Manager – Customize and Control Cart page, Add to Cart button,... |
| CVE-2025-49998 | MEDIUM | 5.4 | 0.3% | Jun 20, 2025 | Missing Authorization vulnerability in Wetail WooCommerce Fortnox Integration woocommerce-fortnox-integration allows Exp... |
| CVE-2025-49997 | MEDIUM | 5.3 | 0.3% | Jun 20, 2025 | Missing Authorization vulnerability in Syed Balkhi Giveaways and Contests by RafflePress rafflepress allows Accessing Fu... |
| CVE-2025-49996 | MEDIUM | 5.3 | 0.3% | Jun 20, 2025 | Missing Authorization vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) wp-stats-manager allows Acces... |
| CVE-2025-49995 | MEDIUM | 5.3 | 0.3% | Jun 20, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in dFactory Download Attachments download-attachments all... |
| CVE-2025-49993 | MEDIUM | 5.3 | 0.2% | Jun 20, 2025 | Missing Authorization vulnerability in csarturas Cookie-Script.com cookie-script-com allows Exploiting Incorrectly Confi... |
| CVE-2025-49991 | MEDIUM | 5.3 | 0.3% | Jun 20, 2025 | Missing Authorization vulnerability in tggfref WP-Recall allows Accessing Functionality Not Properly Constrained by ACLs... |
| CVE-2025-49990 | MEDIUM | 5.3 | 0.2% | Jun 20, 2025 | Missing Authorization vulnerability in contentstudio Contentstudio contentstudio allows Accessing Functionality Not Prop... |
| CVE-2025-49989 | MEDIUM | 5.3 | 0.3% | Jun 20, 2025 | Missing Authorization vulnerability in App Cheap App Builder app-builder allows Exploiting Incorrectly Configured Access... |
| CVE-2025-49988 | MEDIUM | 5.3 | 0.4% | Jun 20, 2025 | Missing Authorization vulnerability in Renzo Johnson Contact Form 7 AWeber Extension integrate-contact-form-7-and-aweber... |
| CVE-2025-49987 | MEDIUM | 5.3 | 0.2% | Jun 20, 2025 | Missing Authorization vulnerability in WPFactory CRM ERP Business Solution crm-erp-business-solution allows Exploiting I... |
| CVE-2025-49986 | MEDIUM | 5.3 | 0.2% | Jun 20, 2025 | Missing Authorization vulnerability in thanhtungtnt Video List Manager video-list-manager allows Accessing Functionality... |
| CVE-2025-49985 | MEDIUM | 4.9 | 0.2% | Jun 20, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Ali Irani Auto Upload Images auto-upload-images allows Server Side R... |
| CVE-2025-49984 | MEDIUM | 4.9 | 0.2% | Jun 20, 2025 | Server-Side Request Forgery (SSRF) vulnerability in blubrry PowerPress Podcasting powerpress allows Server Side Request ... |
| CVE-2025-49983 | MEDIUM | 4.9 | 0.2% | Jun 20, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Joe Hoyle WPThumb wp-thumb allows Server Side Request Forgery.This i... |
| CVE-2025-49982 | MEDIUM | 4.3 | 0.2% | Jun 20, 2025 | Missing Authorization vulnerability in aguilatechnologies WP Customer Area customer-area allows Exploiting Incorrectly C... |
| CVE-2025-49981 | MEDIUM | 4.3 | 0.2% | Jun 20, 2025 | Missing Authorization vulnerability in mahabub81 User Roles and Capabilities user-roles-and-capabilities allows Exploiti... |
| CVE-2025-49980 | MEDIUM | 4.3 | 0.2% | Jun 20, 2025 | Missing Authorization vulnerability in WP Event Manager WP User Profile Avatar wp-user-profile-avatar allows Exploiting ... |
| CVE-2025-49979 | MEDIUM | 4.3 | 0.2% | Jun 20, 2025 | Missing Authorization vulnerability in slui Media Hygiene media-hygiene allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-49978 | MEDIUM | 4.3 | 0.3% | Jun 20, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in eyecix JobSearch wp-jobsearch allows Exploiting Incorr... |
| CVE-2025-49977 | MEDIUM | 4.3 | 0.1% | Jun 20, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Cross S... |
| CVE-2025-49976 | MEDIUM | 4.3 | 0.2% | Jun 20, 2025 | Missing Authorization vulnerability in WANotifier Notifier notifier allows Exploiting Incorrectly Configured Access Cont... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now