2025 CVE Vulnerabilities
45,207 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36361 | HIGH | 8.8 | 0.2% | Oct 24, 2025 | IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user ... |
| CVE-2025-12136 | MEDIUM | 6.8 | 0.4% | Oct 24, 2025 | The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Server-Side Request Forgery... |
| CVE-2025-12134 | MEDIUM | 5.3 | 0.2% | Oct 24, 2025 | The ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns plugin for Wo... |
| CVE-2025-10680 | HIGH | 8.8 | 6.9% | Oct 24, 2025 | OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell comma... |
| CVE-2025-12096 | MEDIUM | 6.4 | 0.2% | Oct 24, 2025 | The Simple Excel Pricelist for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pr... |
| CVE-2025-12072 | MEDIUM | 4.3 | 0.1% | Oct 24, 2025 | The Disable Content Editor For Specific Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in all... |
| CVE-2025-12028 | HIGH | 8.8 | 0.2% | Oct 24, 2025 | The IndieAuth plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5... |
| CVE-2025-12017 | MEDIUM | 6.1 | 0.2% | Oct 24, 2025 | The VNPAY Payment gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' paramet... |
| CVE-2025-12016 | MEDIUM | 4.4 | 0.2% | Oct 24, 2025 | The qnotsquiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qnotsquiz_custom_start_text' pa... |
| CVE-2025-12014 | MEDIUM | 4.3 | 0.2% | Oct 24, 2025 | The NGINX Cache Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2025-11992 | MEDIUM | 6.1 | 0.2% | Oct 24, 2025 | The Multi Item Responsive Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2025-11889 | HIGH | 7.2 | 0.6% | Oct 24, 2025 | The AIO Forms – Craft Complex Forms Easily plugin for WordPress is vulnerable to arbitrary file uploads due to missing f... |
| CVE-2025-11887 | MEDIUM | 4.3 | 0.2% | Oct 24, 2025 | The Supervisor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check... |
| CVE-2025-11504 | HIGH | 7.5 | 0.3% | Oct 24, 2025 | The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9... |
| CVE-2025-11257 | MEDIUM | 4.3 | 0.2% | Oct 24, 2025 | The LLM Hubspot Blog Import plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap... |
| CVE-2025-11253 | CRITICAL | 9.8 | 0.4% | Oct 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aksis Technology I... |
| CVE-2025-11172 | MEDIUM | 4.3 | 0.2% | Oct 24, 2025 | The Check Plagiarism plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2025-10902 | MEDIUM | 4.3 | 0.2% | Oct 24, 2025 | The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabilit... |
| CVE-2025-10901 | MEDIUM | 4.3 | 0.2% | Oct 24, 2025 | The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil... |
| CVE-2025-10749 | MEDIUM | 5.4 | 0.2% | Oct 24, 2025 | The Microsoft Azure Storage for WordPress plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Deletion in... |
| CVE-2025-10748 | MEDIUM | 6.5 | 0.3% | Oct 24, 2025 | The RapidResult plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, and inc... |
| CVE-2025-10740 | MEDIUM | 6.3 | 0.2% | Oct 24, 2025 | The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access to functionality provid... |
| CVE-2025-10701 | MEDIUM | 6.4 | 0.2% | Oct 24, 2025 | The Time Clock – A WordPress Employee & Volunteer Time Clock Plugin for WordPress is vulnerable to Stored Cross-Site Scr... |
| CVE-2025-6440 | CRITICAL | 9.8 | 31.8% | Oct 24, 2025 | The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress the... |
| CVE-2025-62868 | HIGH | 8.1 | 0.4% | Oct 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now