2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12388 | MEDIUM | 6.4 | 0.2% | Nov 5, 2025 | The B Carousel Block – Responsive Image and Content Carousel plugin for WordPress is vulnerable to Server-Side Request F... |
| CVE-2025-12384 | HIGH | 8.6 | 0.3% | Nov 5, 2025 | The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized acce... |
| CVE-2025-12139 | HIGH | 7.5 | 2.2% | Nov 5, 2025 | The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitiv... |
| CVE-2025-11917 | MEDIUM | 6.4 | 0.2% | Nov 5, 2025 | The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, ... |
| CVE-2025-11373 | MEDIUM | 4.3 | 0.2% | Nov 5, 2025 | The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel... |
| CVE-2025-6027 | MEDIUM | 6.3 | 0.2% | Nov 5, 2025 | The Ace User Management WordPress plugin through 2.0.3 does not properly validate that a password reset token is associa... |
| CVE-2025-21079 | HIGH | 8.1 | 0.4% | Nov 5, 2025 | Improper input validation in Samsung Members prior to version 5.5.01.3 allows remote attackers to connect arbitrary URL ... |
| CVE-2025-21078 | MEDIUM | 6.5 | 0.2% | Nov 5, 2025 | Use of insufficiently random value of secretKey in Smart Switch prior to version 3.7.68.6 allows adjacent attackers to a... |
| CVE-2025-21077 | LOW | 3.3 | 0.1% | Nov 5, 2025 | Improper input validation in Samsung Email prior to version 6.2.06.0 allows local attackers to launch arbitrary activity... |
| CVE-2025-21076 | MEDIUM | 5.5 | 0.1% | Nov 5, 2025 | Improper handling of insufficient permissions or privileges in Samsung Account prior to version 15.5.00.18 allows local ... |
| CVE-2025-21075 | HIGH | 7.5 | 0.2% | Nov 5, 2025 | Out-of-bounds write in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-b... |
| CVE-2025-21074 | HIGH | 7.5 | 0.2% | Nov 5, 2025 | Out-of-bounds read in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bo... |
| CVE-2025-21073 | MEDIUM | 4.1 | 0.2% | Nov 5, 2025 | Insecure default configuration in USB connection mode prior to SMR Nov-2025 Release 1 allows privileged physical attacke... |
| CVE-2025-21071 | MEDIUM | 4.4 | 0.1% | Nov 5, 2025 | Out-of-bounds write in handling opcode in fingerprint trustlet prior to SMR Nov-2025 Release 1 allows local privileged a... |
| CVE-2025-11749 | CRITICAL | 9.8 | 75.8% | Nov 5, 2025 | The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
| CVE-2025-11072 | MEDIUM | 5.3 | 0.3% | Nov 5, 2025 | The MelAbu WP Download Counter Button WordPress plugin through 1.8.6.7 does not validate the path of files to be downloa... |
| CVE-2025-10873 | MEDIUM | 5.3 | 0.2% | Nov 5, 2025 | The ElementInvader Addons for Elementor WordPress plugin before 1.4.1 allows unauthenticated user to send arbitrary e-ma... |
| CVE-2025-10567 | MEDIUM | 6.3 | 0.2% | Nov 5, 2025 | The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its check... |
| CVE-2025-12197 | HIGH | 7.5 | 15.2% | Nov 5, 2025 | The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15... |
| CVE-2025-11162 | MEDIUM | 6.4 | 0.2% | Nov 5, 2025 | The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2025-64455 | — | — | — | Nov 5, 2025 | Rejected reason: Not used |
| CVE-2025-64454 | — | — | — | Nov 5, 2025 | Rejected reason: Not used |
| CVE-2025-64453 | — | — | — | Nov 5, 2025 | Rejected reason: Not used |
| CVE-2025-64452 | — | — | — | Nov 5, 2025 | Rejected reason: Not used |
| CVE-2025-64451 | — | — | — | Nov 5, 2025 | Rejected reason: Not used |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now