2025 CVE Vulnerabilities

45,209 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62013MEDIUM4.3Missing Authorization vulnerability in POSIMYTH UiChemy uichemy.This issue affects UiChemy: from n/a through <= 4.0.0.
CVE-2025-62009MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") UPC/EAN/GTIN Code Generator upc-ean...
CVE-2025-62008HIGH8.8Deserialization of Untrusted Data vulnerability in acowebs Product Table For WooCommerce product-table-for-woocommerce.T...
CVE-2025-62007HIGH8.8Incorrect Privilege Assignment vulnerability in bPlugins Voice Feedback voice-feedback allows Privilege Escalation.This ...
CVE-2025-62006MEDIUM5.4Missing Authorization vulnerability in VeronaLabs WP SMS wp-sms.This issue affects WP SMS: from n/a through <= 7.0.1.
CVE-2025-62005HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships all...
CVE-2025-60332HIGH7.5A NULL pointer dereference in the SetWLanRadioSettings function of D-Link DIR-823G A1 v1.0.2B05 allows attackers to caus...
CVE-2025-60331HIGH7.5D-Link DIR-823G A1 v1.0.2B05 was discovered to contain a buffer overflow in the FillMacCloneMac parameter in the /EXCU_S...
CVE-2025-60246HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weissmike Simple F...
CVE-2025-60238CRITICAL9.8Deserialization of Untrusted Data vulnerability in universam UNIVERSAM universam-demo allows Object Injection.This issue...
CVE-2025-60234HIGH8.8Deserialization of Untrusted Data vulnerability in designthemes Single Property single-property allows Object Injection....
CVE-2025-60232CRITICAL9.8Deserialization of Untrusted Data vulnerability in quantumcloud KBx Pro Ultimate knowledgebase-helpdesk-pro allows Objec...
CVE-2025-60228HIGH8.8Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue ...
CVE-2025-60227HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes wp-pi...
CVE-2025-60226CRITICAL9.8Deserialization of Untrusted Data vulnerability in axiomthemes White Rabbit whiterabbit allows Object Injection.This iss...
CVE-2025-60225CRITICAL9.8Deserialization of Untrusted Data vulnerability in AncoraThemes BugsPatrol bugspatrol allows Object Injection.This issue...
CVE-2025-60224CRITICAL9.8Deserialization of Untrusted Data vulnerability in wpshuffle Subscribe to Download subscribe-to-download allows Object I...
CVE-2025-60222HIGH8.8Incorrect Privilege Assignment vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows...
CVE-2025-60221CRITICAL9.8Deserialization of Untrusted Data vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Object Injec...
CVE-2025-60220CRITICAL9.8Incorrect Privilege Assignment vulnerability in pebas CouponXxL couponxxl allows Privilege Escalation.This issue affects...
CVE-2025-60217HIGH7.7Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ypromo PT Luxa Addons pt...
CVE-2025-60216CRITICAL9.8Deserialization of Untrusted Data vulnerability in BoldThemes Addison addison allows Object Injection.This issue affects...
CVE-2025-60215HIGH8.8Deserialization of Untrusted Data vulnerability in designthemes Kriya kriya allows Object Injection.This issue affects K...
CVE-2025-60214CRITICAL9.8Deserialization of Untrusted Data vulnerability in BoldThemes Goldenblatt goldenblatt allows Object Injection.This issue...
CVE-2025-60213CRITICAL9.8Deserialization of Untrusted Data vulnerability in Whitebox-Studio Scape scape allows Object Injection.This issue affect...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now