2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12388MEDIUM6.4The B Carousel Block – Responsive Image and Content Carousel plugin for WordPress is vulnerable to Server-Side Request F...
CVE-2025-12384HIGH8.6The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized acce...
CVE-2025-12139HIGH7.5The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitiv...
CVE-2025-11917MEDIUM6.4The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, ...
CVE-2025-11373MEDIUM4.3The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel...
CVE-2025-6027MEDIUM6.3The Ace User Management WordPress plugin through 2.0.3 does not properly validate that a password reset token is associa...
CVE-2025-21079HIGH8.1Improper input validation in Samsung Members prior to version 5.5.01.3 allows remote attackers to connect arbitrary URL ...
CVE-2025-21078MEDIUM6.5Use of insufficiently random value of secretKey in Smart Switch prior to version 3.7.68.6 allows adjacent attackers to a...
CVE-2025-21077LOW3.3Improper input validation in Samsung Email prior to version 6.2.06.0 allows local attackers to launch arbitrary activity...
CVE-2025-21076MEDIUM5.5Improper handling of insufficient permissions or privileges in Samsung Account prior to version 15.5.00.18 allows local ...
CVE-2025-21075HIGH7.5Out-of-bounds write in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-b...
CVE-2025-21074HIGH7.5Out-of-bounds read in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bo...
CVE-2025-21073MEDIUM4.1Insecure default configuration in USB connection mode prior to SMR Nov-2025 Release 1 allows privileged physical attacke...
CVE-2025-21071MEDIUM4.4Out-of-bounds write in handling opcode in fingerprint trustlet prior to SMR Nov-2025 Release 1 allows local privileged a...
CVE-2025-11749CRITICAL9.8The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2025-11072MEDIUM5.3The MelAbu WP Download Counter Button WordPress plugin through 1.8.6.7 does not validate the path of files to be downloa...
CVE-2025-10873MEDIUM5.3The ElementInvader Addons for Elementor WordPress plugin before 1.4.1 allows unauthenticated user to send arbitrary e-ma...
CVE-2025-10567MEDIUM6.3The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its check...
CVE-2025-12197HIGH7.5The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15...
CVE-2025-11162MEDIUM6.4The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2025-64455Rejected reason: Not used
CVE-2025-64454Rejected reason: Not used
CVE-2025-64453Rejected reason: Not used
CVE-2025-64452Rejected reason: Not used
CVE-2025-64451Rejected reason: Not used

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now