2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-25154 | HIGH | 7.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in scweber Custom Comment Notifications custom-comment-notifications all... |
| CVE-2025-25153 | HIGH | 7.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in djjmz Simple Auto Tag simple-auto-tag allows Stored XSS.This issue af... |
| CVE-2025-25152 | HIGH | 7.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in LukaszWiecek Smart DoFollow smart-dofollow allows Stored XSS.This iss... |
| CVE-2025-25151 | HIGH | 8.5 | 0.4% | Feb 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix uListing ... |
| CVE-2025-25149 | HIGH | 7.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Danillo Nunes Login-box login-box allows Stored XSS.This issue affect... |
| CVE-2025-25148 | HIGH | 7.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ElbowRobo Read More Copy Link read-more-copy-link allows Stored XSS.T... |
| CVE-2025-25147 | HIGH | 7.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Phillip.Gooch Auto SEO auto-seo allows Stored XSS.This issue affects ... |
| CVE-2025-25144 | HIGH | 7.1 | 0.3% | Feb 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in theasys Theasys th... |
| CVE-2025-25141 | HIGH | 7.5 | 0.7% | Feb 7, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-25140 | HIGH | 7.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Scriptonite Simple User Profile simple-user-profile allows Stored XSS... |
| CVE-2025-25139 | HIGH | 7.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Cynob IT Consultancy WP Custom Post RSS Feed wp-custom-post-rss-feed ... |
| CVE-2025-25138 | HIGH | 7.1 | 0.2% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Rishi On Page SEO + Whatsapp Chat Button ops-robots-txt allows Stored... |
| CVE-2025-25135 | HIGH | 7.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Victor Barkalov Custom Links On Admin Dashboard Toolbar customize-wpa... |
| CVE-2025-25128 | HIGH | 7.1 | 0.2% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in orlandolac Facilita Form Tracker facilita-form-tracker allows Stored ... |
| CVE-2025-25126 | HIGH | 7.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in zmseo ZMSEO zmseo allows Stored XSS.This issue affects ZMSEO: from n/... |
| CVE-2025-25125 | HIGH | 7.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in CyrilG Fyrebox Quizzes fyrebox-shortcode allows Stored XSS.This issue... |
| CVE-2025-25123 | HIGH | 7.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in xdark Easy Related Posts easy-related-posts allows Stored XSS.This is... |
| CVE-2025-25116 | HIGH | 7.6 | 0.4% | Feb 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in sudipto Link to UR... |
| CVE-2025-25104 | HIGH | 7.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in mraliende URL-Preview-Box good-url-preview-box allows Cross Site Requ... |
| CVE-2025-25088 | HIGH | 7.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in blackus3r WP Keyword Monitor wp-keyword-monitor allows Cross Site Req... |
| CVE-2025-25075 | HIGH | 7.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Show notice or message on admin area show-notice-or-message... |
| CVE-2025-25074 | HIGH | 7.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Nirmal Kumar Ram WP Social Stream wp-social-stream allows Stored XSS.... |
| CVE-2025-25072 | HIGH | 7.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in thunderbax WP Admin Custom Page wp-admin-custom-page allows Stored XS... |
| CVE-2025-25071 | HIGH | 7.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in topplugins Vignette Ads vignete-ads allows Stored XSS.This issue affe... |
| CVE-2025-0304 | HIGH | 7.8 | 0.2% | Feb 7, 2025 | in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sens... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now