2025 CVE Vulnerabilities

45,223 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9947MEDIUM4.9The Custom 404 Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘path’ parameter in all versio...
CVE-2025-9626MEDIUM4.3The Page Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2025-9621MEDIUM4.3The WidgetPack Comment System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an...
CVE-2025-8682MEDIUM4.3The Newsup theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on th...
CVE-2025-8606LOW2.4The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less ...
CVE-2025-8593HIGH8.8The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in versions less than, ...
CVE-2025-8484MEDIUM5.3The Code Quality Control Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in version 2.1 throug...
CVE-2025-7652MEDIUM6.4The Easy Plugin Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eps' shortcode...
CVE-2025-6439CRITICAL9.8The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress the...
CVE-2025-58301MEDIUM5.5Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect ...
CVE-2025-58300MEDIUM5.5Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect ...
CVE-2025-58293MEDIUM5.5Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affe...
CVE-2025-58289MEDIUM5.5Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affe...
CVE-2025-11596CRITICAL9.8A vulnerability was determined in code-projects E-Commerce Website 1.0. The affected element is an unknown function of t...
CVE-2025-11595CRITICAL9.8A vulnerability was found in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function o...
CVE-2025-10376MEDIUM4.3The Course Redirects for Learndash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...
CVE-2025-10375MEDIUM4.3The Web Accessibility By accessiBe plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...
CVE-2025-10190MEDIUM6.4The WP Easy Toggles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'toggles' shortco...
CVE-2025-10175MEDIUM6.5The WP Links Page plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and ...
CVE-2025-10167MEDIUM6.4The Stock History & Reports Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2025-10129MEDIUM6.4The WordPress Live Webcam Widget & Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p...
CVE-2025-6553CRITICAL9.8The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida...
CVE-2025-58299MEDIUM5.5Use After Free (UAF) vulnerability in the storage management module. Successful exploitation of this vulnerability may a...
CVE-2025-58298MEDIUM5.5Data processing error vulnerability in the package management module. Successful exploitation of this vulnerability may ...
CVE-2025-58297MEDIUM5.5Buffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availabili...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now