2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3743 | MEDIUM | 5.3 | 0.3% | Apr 25, 2025 | The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to... |
| CVE-2025-3923 | MEDIUM | 5.3 | 0.3% | Apr 25, 2025 | The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposure... |
| CVE-2025-3861 | MEDIUM | 5.4 | 0.2% | Apr 25, 2025 | The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modifi... |
| CVE-2025-2580 | MEDIUM | 4.9 | 0.2% | Apr 25, 2025 | The Contact Form by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in a... |
| CVE-2025-0671 | MEDIUM | 6.1 | 0.2% | Apr 25, 2025 | The Icegram Express WordPress plugin before 5.7.50 does not sanitise and escape some of its Template settings, which co... |
| CVE-2025-46599 | MEDIUM | 6.8 | 0.4% | Apr 25, 2025 | CNCF K3s 1.32 before 1.32.4-rc1+k3s1 has a Kubernetes kubelet configuration change with the unintended consequence that,... |
| CVE-2025-3775 | MEDIUM | 6.5 | 0.2% | Apr 25, 2025 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) pl... |
| CVE-2025-3752 | MEDIUM | 6.4 | 0.3% | Apr 25, 2025 | The Able Player, accessible HTML5 media player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2025-46595 | MEDIUM | 6.4 | 0.2% | Apr 25, 2025 | An XSS issue was discovered in the Flag module before 1.x-3.6.2 for Backdrop CMS. Flag is a module that allows flags to ... |
| CVE-2025-46547 | MEDIUM | 6.1 | 0.1% | Apr 25, 2025 | In Sherpa Orchestrator 141851, the web application lacks protection against CSRF attacks, with resultant effects of an a... |
| CVE-2025-46545 | MEDIUM | 4.8 | 0.2% | Apr 25, 2025 | In Sherpa Orchestrator 141851, the functionality for adding or updating licenses allows for stored XSS attacks by an adm... |
| CVE-2025-46544 | MEDIUM | 6.5 | 0.2% | Apr 25, 2025 | In Sherpa Orchestrator 141851, a low-privileged user can elevate their privileges by creating new users and roles. |
| CVE-2025-3749 | MEDIUM | 6.4 | 0.3% | Apr 24, 2025 | The Breeze Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cal_size’ parameter in all... |
| CVE-2025-43861 | MEDIUM | 5.4 | 0.2% | Apr 24, 2025 | ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 2f177dc, ManageWiki is vulnerable to... |
| CVE-2025-29529 | MEDIUM | 6.5 | 0.3% | Apr 24, 2025 | ITC Systems Multiplan/Matrix OneCard platform v3.7.4.1002 was discovered to contain a SQL injection vulnerability via th... |
| CVE-2025-46542 | MEDIUM | 6.5 | 0.2% | Apr 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeXpert Xpert T... |
| CVE-2025-46541 | MEDIUM | 5.9 | 0.2% | Apr 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elrata_ WP-reCAPTC... |
| CVE-2025-46540 | MEDIUM | 6.5 | 0.2% | Apr 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Mok GNA Sear... |
| CVE-2025-46538 | MEDIUM | 6.5 | 0.2% | Apr 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webplanetsoft Inli... |
| CVE-2025-46536 | MEDIUM | 6.5 | 0.2% | Apr 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RichardHarrison Ca... |
| CVE-2025-46534 | MEDIUM | 6.5 | 0.2% | Apr 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DanielRiera Image ... |
| CVE-2025-46533 | MEDIUM | 5.9 | 0.2% | Apr 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdrift.no Landing... |
| CVE-2025-46532 | MEDIUM | 6.5 | 0.2% | Apr 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Haris Zulfiqar Too... |
| CVE-2025-46531 | MEDIUM | 4.9 | 0.2% | Apr 24, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Ankur Vishwakarma WP AVCL Automation Helper (formerly WPFlyLeads) wo... |
| CVE-2025-46529 | MEDIUM | 5.9 | 0.2% | Apr 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StressFree Sites B... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now