2025 CVE Vulnerabilities
45,224 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1362 | MEDIUM | 4.3 | 0.2% | Mar 9, 2025 | The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not have CSRF c... |
| CVE-2025-2114 | MEDIUM | 6.3 | 0.6% | Mar 9, 2025 | A vulnerability, which was classified as problematic, has been found in Shenzhen Sixun Software Sixun Shanghui Group Bus... |
| CVE-2025-27840 | MEDIUM | 6.8 | 1.3% | Mar 8, 2025 | Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory). |
| CVE-2025-1664 | MEDIUM | 5.4 | 0.2% | Mar 8, 2025 | The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ... |
| CVE-2025-1783 | MEDIUM | 5.4 | 0.2% | Mar 8, 2025 | The Gallery Styles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gallery Block in all versio... |
| CVE-2025-1325 | MEDIUM | 6.3 | 0.3% | Mar 8, 2025 | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to arbitrary shortcode executi... |
| CVE-2025-1324 | MEDIUM | 5.4 | 0.2% | Mar 8, 2025 | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2025-1322 | MEDIUM | 4.3 | 0.4% | Mar 8, 2025 | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Information Exposure in all... |
| CVE-2025-1287 | MEDIUM | 5.4 | 0.3% | Mar 8, 2025 | The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre... |
| CVE-2025-1504 | MEDIUM | 6.5 | 0.3% | Mar 8, 2025 | The Post Lockdown plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.0.2... |
| CVE-2025-1481 | MEDIUM | 4.3 | 0.3% | Mar 8, 2025 | The Shortcode Cleaner Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability... |
| CVE-2025-1261 | MEDIUM | 5.4 | 0.2% | Mar 8, 2025 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting ... |
| CVE-2025-27826 | MEDIUM | 6.4 | 0.2% | Mar 7, 2025 | An XSS issue was discovered in the Bootstrap Lite theme before 1.x-1.4.5 for Backdrop CMS. It doesn't sufficiently sanit... |
| CVE-2025-27825 | MEDIUM | 6.4 | 0.2% | Mar 7, 2025 | An XSS issue was discovered in the Bootstrap 5 Lite theme before 1.x-1.0.3 for Backdrop CMS. It doesn't sufficiently san... |
| CVE-2025-27824 | MEDIUM | 6.4 | 0.2% | Mar 7, 2025 | An XSS issue was discovered in the Link iframe formatter module before 1.x-1.1.1 for Backdrop CMS. It doesn't sufficient... |
| CVE-2025-27823 | MEDIUM | 6.4 | 0.2% | Mar 7, 2025 | An issue was discovered in the Mail Disguise module before 1.x-1.0.5 for Backdrop CMS. It enables a website to obfuscate... |
| CVE-2025-26643 | MEDIUM | 5.4 | 0.7% | Mar 7, 2025 | The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing ... |
| CVE-2025-27518 | MEDIUM | 6.9 | 0.5% | Mar 7, 2025 | Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for productio... |
| CVE-2025-27152 | MEDIUM | 5.3 | 0.8% | Mar 7, 2025 | axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather tha... |
| CVE-2025-25617 | MEDIUM | 4.3 | 0.4% | Mar 7, 2025 | Incorrect Access Control in Unifiedtransform 2.X leads to Privilege Escalation allowing teachers to create syllabus. |
| CVE-2025-2090 | MEDIUM | 5.1 | 0.4% | Mar 7, 2025 | A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this is... |
| CVE-2025-2089 | MEDIUM | 5.4 | 0.5% | Mar 7, 2025 | A vulnerability has been found in StarSea99 starsea-mall 1.0/2.X and classified as critical. Affected by this vulnerabil... |
| CVE-2025-2087 | MEDIUM | 6.1 | 0.4% | Mar 7, 2025 | A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects s... |
| CVE-2025-2086 | MEDIUM | 6.1 | 0.3% | Mar 7, 2025 | A vulnerability classified as problematic was found in StarSea99 starsea-mall 1.0. This vulnerability affects unknown co... |
| CVE-2025-2085 | MEDIUM | 6.1 | 0.3% | Mar 7, 2025 | A vulnerability classified as problematic has been found in StarSea99 starsea-mall 1.0. This affects an unknown part of ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now