2025 CVE Vulnerabilities
45,223 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9947 | MEDIUM | 4.9 | 0.3% | Oct 11, 2025 | The Custom 404 Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘path’ parameter in all versio... |
| CVE-2025-9626 | MEDIUM | 4.3 | 0.2% | Oct 11, 2025 | The Page Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1... |
| CVE-2025-9621 | MEDIUM | 4.3 | 0.1% | Oct 11, 2025 | The WidgetPack Comment System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an... |
| CVE-2025-8682 | MEDIUM | 4.3 | 0.2% | Oct 11, 2025 | The Newsup theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on th... |
| CVE-2025-8606 | LOW | 2.4 | 0.1% | Oct 11, 2025 | The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less ... |
| CVE-2025-8593 | HIGH | 8.8 | 0.4% | Oct 11, 2025 | The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in versions less than, ... |
| CVE-2025-8484 | MEDIUM | 5.3 | 0.3% | Oct 11, 2025 | The Code Quality Control Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in version 2.1 throug... |
| CVE-2025-7652 | MEDIUM | 6.4 | 0.2% | Oct 11, 2025 | The Easy Plugin Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eps' shortcode... |
| CVE-2025-6439 | CRITICAL | 9.8 | 0.7% | Oct 11, 2025 | The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress the... |
| CVE-2025-58301 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect ... |
| CVE-2025-58300 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect ... |
| CVE-2025-58293 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affe... |
| CVE-2025-58289 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affe... |
| CVE-2025-11596 | CRITICAL | 9.8 | 0.4% | Oct 11, 2025 | A vulnerability was determined in code-projects E-Commerce Website 1.0. The affected element is an unknown function of t... |
| CVE-2025-11595 | CRITICAL | 9.8 | 0.4% | Oct 11, 2025 | A vulnerability was found in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function o... |
| CVE-2025-10376 | MEDIUM | 4.3 | 0.1% | Oct 11, 2025 | The Course Redirects for Learndash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... |
| CVE-2025-10375 | MEDIUM | 4.3 | 0.1% | Oct 11, 2025 | The Web Accessibility By accessiBe plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... |
| CVE-2025-10190 | MEDIUM | 6.4 | 0.2% | Oct 11, 2025 | The WP Easy Toggles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'toggles' shortco... |
| CVE-2025-10175 | MEDIUM | 6.5 | 0.4% | Oct 11, 2025 | The WP Links Page plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and ... |
| CVE-2025-10167 | MEDIUM | 6.4 | 0.2% | Oct 11, 2025 | The Stock History & Reports Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2025-10129 | MEDIUM | 6.4 | 0.2% | Oct 11, 2025 | The WordPress Live Webcam Widget & Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p... |
| CVE-2025-6553 | CRITICAL | 9.8 | 0.7% | Oct 11, 2025 | The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida... |
| CVE-2025-58299 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Use After Free (UAF) vulnerability in the storage management module. Successful exploitation of this vulnerability may a... |
| CVE-2025-58298 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Data processing error vulnerability in the package management module. Successful exploitation of this vulnerability may ... |
| CVE-2025-58297 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Buffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availabili... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now