2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6327 | CRITICAL | 10 | 0.5% | Nov 6, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in KingAddons.com King Addons for Elementor king-addons al... |
| CVE-2025-6325 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | Incorrect Privilege Assignment vulnerability in KingAddons.com King Addons for Elementor king-addons allows Privilege Es... |
| CVE-2025-62065 | CRITICAL | 9.9 | 0.3% | Nov 6, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Rometheme RTMKit rometheme-for-elementor.This issue aff... |
| CVE-2025-62064 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Elated-Themes Search & Go search-and-go allows... |
| CVE-2025-62047 | CRITICAL | 9.9 | 0.4% | Nov 6, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Case-Themes Case Addons case-addons.This issue affects ... |
| CVE-2025-62016 | CRITICAL | 9.9 | 0.3% | Nov 6, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in hogash KALLYAS kallyas.This issue affects KALLYAS: from... |
| CVE-2025-60245 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | Deserialization of Untrusted Data vulnerability in WP User Manager WP User Manager wp-user-manager allows Object Injecti... |
| CVE-2025-60243 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | Incorrect Privilege Assignment vulnerability in Holest Engineering Selling Commander for WooCommerce selling-commander-c... |
| CVE-2025-60235 | CRITICAL | 10 | 0.4% | Nov 6, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Plugify Support Ticket System for WooCommerce (Premium)... |
| CVE-2025-60207 | CRITICAL | 10 | 0.4% | Nov 6, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Addify Custom User Registration Fields for WooCommerce ... |
| CVE-2025-60195 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | Incorrect Privilege Assignment vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Privilege Escalatio... |
| CVE-2025-58998 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | Deserialization of Untrusted Data vulnerability in Cristián Lávaque s2Member s2member allows Object Injection.This issue... |
| CVE-2025-58996 | CRITICAL | 9.1 | 0.4% | Nov 6, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Helmut Wandl Advanced Settings advanced-settings allows... |
| CVE-2025-58636 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Keap/Infusionsoft gf-infusionsoft allows O... |
| CVE-2025-58627 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore all... |
| CVE-2025-53283 | CRITICAL | 10 | 0.4% | Nov 6, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in borisolhor Drop Uploader for CF7 - Drag&Drop File Uploa... |
| CVE-2025-53242 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | Deserialization of Untrusted Data vulnerability in VictorThemes Seil seil allows Object Injection.This issue affects Sei... |
| CVE-2025-52773 | CRITICAL | 9.3 | 0.3% | Nov 6, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hiecor HieCOR Paym... |
| CVE-2025-49393 | CRITICAL | 9.8 | 0.5% | Nov 6, 2025 | Deserialization of Untrusted Data vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Object Injection.T... |
| CVE-2025-49372 | CRITICAL | 10 | 0.4% | Nov 6, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticke... |
| CVE-2025-48089 | CRITICAL | 9.3 | 0.3% | Nov 6, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rainbow-Themes Edu... |
| CVE-2025-47588 | CRITICAL | 9.1 | 0.4% | Nov 6, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in acowebs Dynamic Pricing With Discount Rules f... |
| CVE-2025-32222 | CRITICAL | 9.9 | 0.4% | Nov 6, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Widgetlogic.org Widget Logic widget-logic all... |
| CVE-2025-64164 | CRITICAL | 9.8 | 0.5% | Nov 6, 2025 | Dataease is an open source data visualization analysis tool. In versions 2.10.14 and below, DataEase did not properly fi... |
| CVE-2025-64163 | CRITICAL | 9.8 | 1.0% | Nov 6, 2025 | DataEase is an open source data visualization analysis tool. In versions 2.10.14 and below, the vendor added a blacklist... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now