2025 CVE Vulnerabilities
45,202 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27359 | MEDIUM | 4.3 | 0.1% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Seerox WP Media File Type Manager wp-media-file-type-manager allows C... |
| CVE-2025-27334 | MEDIUM | 6.5 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ángel C. Simple Go... |
| CVE-2025-26593 | MEDIUM | 4.3 | 0.2% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in FasterThemes FastBook fastbook-responsive-appointment-booking-and-sch... |
| CVE-2025-24778 | MEDIUM | 5.4 | 0.3% | Jun 6, 2025 | Missing Authorization vulnerability in De paragon No Spam At All no-spam-at-all allows Exploiting Incorrectly Configured... |
| CVE-2025-24776 | MEDIUM | 5.4 | 0.3% | Jun 6, 2025 | Missing Authorization vulnerability in codelobster Responsive Flipbooks responsive-flipbooks allows Exploiting Incorrect... |
| CVE-2025-24772 | MEDIUM | 5.4 | 0.1% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in cmsMinds Pay with Contact Form 7 pay-with-contact-form-7 allows Cross... |
| CVE-2025-24763 | MEDIUM | 5.3 | 0.3% | Jun 6, 2025 | Missing Authorization vulnerability in Pascal Casier bbPress API bbp-api allows Exploiting Incorrectly Configured Access... |
| CVE-2025-24762 | MEDIUM | 5.4 | 0.3% | Jun 6, 2025 | Missing Authorization vulnerability in facturaone TicketBAI Facturas para WooCommerce wp-ticketbai allows Exploiting Inc... |
| CVE-2025-23971 | MEDIUM | 5.3 | 0.3% | Jun 6, 2025 | Missing Authorization vulnerability in whassan KI Live Video Conferences ki-live-video-conferences allows Exploiting Inc... |
| CVE-2025-23969 | MEDIUM | 5.3 | 0.3% | Jun 6, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in whassan KI Live Video Confer... |
| CVE-2025-5760 | MEDIUM | 4.9 | 0.4% | Jun 6, 2025 | The Simple History plugin for WordPress is vulnerable to sensitive data exposure via Detective Mode due to improper sani... |
| CVE-2025-5239 | MEDIUM | 6.4 | 0.3% | Jun 6, 2025 | The Domain For Sale plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class_name’ parameter in ... |
| CVE-2025-49077 | MEDIUM | 4.3 | 0.1% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeHigh Dynamic Pricing and Discount Rules discount-and-dynamic-pri... |
| CVE-2025-49076 | MEDIUM | 6.5 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus ... |
| CVE-2025-49075 | MEDIUM | 6.5 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Wishli... |
| CVE-2025-49074 | MEDIUM | 6.5 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Abu Huraira Bin Am... |
| CVE-2025-49068 | MEDIUM | 6.5 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oceanwp Ocean Extr... |
| CVE-2025-49067 | MEDIUM | 6.5 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NasaTheme Nasa Cor... |
| CVE-2025-48337 | MEDIUM | 5.3 | 0.2% | Jun 6, 2025 | Missing Authorization vulnerability in QuickcabWP QuickCab.This issue affects QuickCab: from n/a through 1.3.3. |
| CVE-2025-48335 | MEDIUM | 5.4 | 0.2% | Jun 6, 2025 | Missing Authorization vulnerability in CyberChimps Responsive Plus responsive-add-ons allows Exploiting Incorrectly Conf... |
| CVE-2025-48328 | MEDIUM | 4.3 | 0.1% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Daman Jeet Real Time Validation for Gravity Forms real-time-validatio... |
| CVE-2025-41367 | MEDIUM | 4.8 | 0.3% | Jun 6, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allow... |
| CVE-2025-41366 | MEDIUM | 5.1 | 0.3% | Jun 6, 2025 | In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross-origin resource sharing... |
| CVE-2025-41365 | MEDIUM | 5.1 | 0.3% | Jun 6, 2025 | Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allows an attacker to st... |
| CVE-2025-41364 | MEDIUM | 5.1 | 0.3% | Jun 6, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allow... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now