2025 CVE Vulnerabilities
45,209 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60212 | HIGH | 8.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in designthemes VEDA veda allows Object Injection.This issue affects VED... |
| CVE-2025-60211 | HIGH | 8.8 | 0.4% | Oct 22, 2025 | Incorrect Privilege Assignment vulnerability in extendons WooCommerce Registration Fields Plugin - Custom Signup Fields ... |
| CVE-2025-60210 | CRITICAL | 9.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in wpeverest Everest Forms - Frontend Listing everest-forms-frontend-lis... |
| CVE-2025-60209 | CRITICAL | 9.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets wp-gravity-fo... |
| CVE-2025-60208 | HIGH | 8.8 | 0.2% | Oct 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Tusko Trush Advanced Custom Fields : CPT Options Pages acf-cpt-option... |
| CVE-2025-60206 | CRITICAL | 10 | 0.5% | Oct 22, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Code Injectio... |
| CVE-2025-60176 | MEDIUM | 5.9 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tattersoftware WP ... |
| CVE-2025-60168 | HIGH | 7.1 | 0.1% | Oct 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in integrationshotelrunner HotelRunner Booking Widget hotelrunner allows... |
| CVE-2025-60151 | MEDIUM | 4.7 | 0.2% | Oct 22, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allow... |
| CVE-2025-60135 | MEDIUM | 5.9 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NIKITAS GEORGOPOUL... |
| CVE-2025-60134 | MEDIUM | 4.3 | 0.1% | Oct 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in John James Jacoby WP Media Categories wp-media-categories allows Cros... |
| CVE-2025-60132 | HIGH | 7.1 | 0.1% | Oct 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in johnh10 Video Blogster Lite video-blogster-lite allows Stored XSS.Thi... |
| CVE-2025-60131 | MEDIUM | 5.9 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoefff Werk aan de... |
| CVE-2025-60041 | HIGH | 8.8 | 0.4% | Oct 22, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Iulia Cazan Emails Catch All emails-catch-all ... |
| CVE-2025-60039 | CRITICAL | 9.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in rascals Noisa noisa allows Object Injection.This issue affects Noisa:... |
| CVE-2025-59593 | MEDIUM | 5.9 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Coli... |
| CVE-2025-59580 | HIGH | 8.8 | 0.4% | Oct 22, 2025 | Incorrect Privilege Assignment vulnerability in GoodLayers Goodlayers Core goodlayers-core allows Privilege Escalation.T... |
| CVE-2025-59579 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in PressTigers Simple Job Board simple-job-board allows ... |
| CVE-2025-59578 | MEDIUM | 5.8 | 0.3% | Oct 22, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in wpdesk ShopMagic shopmagic-for-woocommerce allows Ret... |
| CVE-2025-59575 | MEDIUM | 4.9 | 0.3% | Oct 22, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stylemix MasterStudy LMS mas... |
| CVE-2025-59571 | HIGH | 7.1 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes WorkSco... |
| CVE-2025-59566 | HIGH | 7.7 | 0.4% | Oct 22, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Workreap (the... |
| CVE-2025-59564 | HIGH | 8.1 | 0.5% | Oct 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-59558 | HIGH | 8.1 | 0.5% | Oct 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-59557 | CRITICAL | 9.3 | 0.3% | Oct 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeMove Learts A... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now