2025 CVE Vulnerabilities

45,207 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-36361HIGH8.8IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user ...
CVE-2025-12136MEDIUM6.8The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Server-Side Request Forgery...
CVE-2025-12134MEDIUM5.3The ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns plugin for Wo...
CVE-2025-10680HIGH8.8OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell comma...
CVE-2025-12096MEDIUM6.4The Simple Excel Pricelist for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pr...
CVE-2025-12072MEDIUM4.3The Disable Content Editor For Specific Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
CVE-2025-12028HIGH8.8The IndieAuth plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5...
CVE-2025-12017MEDIUM6.1The VNPAY Payment gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' paramet...
CVE-2025-12016MEDIUM4.4The qnotsquiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qnotsquiz_custom_start_text' pa...
CVE-2025-12014MEDIUM4.3The NGINX Cache Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2025-11992MEDIUM6.1The Multi Item Responsive Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-11889HIGH7.2The AIO Forms – Craft Complex Forms Easily plugin for WordPress is vulnerable to arbitrary file uploads due to missing f...
CVE-2025-11887MEDIUM4.3The Supervisor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2025-11504HIGH7.5The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9...
CVE-2025-11257MEDIUM4.3The LLM Hubspot Blog Import plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap...
CVE-2025-11253CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aksis Technology I...
CVE-2025-11172MEDIUM4.3The Check Plagiarism plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2025-10902MEDIUM4.3The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabilit...
CVE-2025-10901MEDIUM4.3The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil...
CVE-2025-10749MEDIUM5.4The Microsoft Azure Storage for WordPress plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Deletion in...
CVE-2025-10748MEDIUM6.5The RapidResult plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, and inc...
CVE-2025-10740MEDIUM6.3The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access to functionality provid...
CVE-2025-10701MEDIUM6.4The Time Clock – A WordPress Employee & Volunteer Time Clock Plugin for WordPress is vulnerable to Stored Cross-Site Scr...
CVE-2025-6440CRITICAL9.8The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress the...
CVE-2025-62868HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now