2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-24713 | MEDIUM | 5.4 | 0.2% | Jan 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder button-generatio... |
| CVE-2025-24712 | MEDIUM | 5.4 | 0.2% | Jan 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Radius Blocks radius-blocks allows Cross Site Request For... |
| CVE-2025-24711 | MEDIUM | 5.4 | 0.2% | Jan 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Popup Box popup-box allows Cross Site Request Forgery.Thi... |
| CVE-2025-24709 | MEDIUM | 6.5 | 0.4% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plethora Plugins P... |
| CVE-2025-24706 | MEDIUM | 6.5 | 0.4% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MultiVendorX Multi... |
| CVE-2025-24705 | MEDIUM | 5.3 | 0.5% | Jan 24, 2025 | Missing Authorization vulnerability in Arshid WooCommerce Quick View woo-quick-view allows Exploiting Incorrectly Config... |
| CVE-2025-24704 | MEDIUM | 6.5 | 0.4% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in grimdonkey Magic t... |
| CVE-2025-24703 | MEDIUM | 4.4 | 0.3% | Jan 24, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Ronald Huereca Comment Edit Core – Simple Comment Editing simple-com... |
| CVE-2025-24702 | MEDIUM | 6.5 | 0.4% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xagio SEO Xagio SE... |
| CVE-2025-24701 | MEDIUM | 4.4 | 0.3% | Jan 24, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Bob Chained Quiz chained-quiz allows Server Side Request Forgery.Thi... |
| CVE-2025-24698 | MEDIUM | 4.3 | 0.2% | Jan 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in g5theme Essential Real Estate essential-real-estate allows Cross Site... |
| CVE-2025-24696 | MEDIUM | 4.3 | 0.2% | Jan 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Shafaet Alam Attire Blocks attire-blocks allows Cross Site Request Fo... |
| CVE-2025-24695 | MEDIUM | 4.4 | 0.3% | Jan 24, 2025 | Server-Side Request Forgery (SSRF) vulnerability in HT Plugins Extensions For CF7 extensions-for-cf7 allows Server Side ... |
| CVE-2025-24693 | MEDIUM | 4.3 | 0.4% | Jan 24, 2025 | Missing Authorization vulnerability in Yehi Advanced Notifications advanced-notifications allows Exploiting Incorrectly ... |
| CVE-2025-24691 | MEDIUM | 4.3 | 0.4% | Jan 24, 2025 | Missing Authorization vulnerability in ctltwp People Lists people-lists allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-24687 | MEDIUM | 6.5 | 0.3% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lars Wallenborn Sh... |
| CVE-2025-24682 | MEDIUM | 4.3 | 0.4% | Jan 24, 2025 | Missing Authorization vulnerability in Michael Super Block Slider super-block-slider allows Exploiting Incorrectly Confi... |
| CVE-2025-24681 | MEDIUM | 5.9 | 0.3% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWax Product Caro... |
| CVE-2025-24679 | MEDIUM | 4.3 | 0.4% | Jan 24, 2025 | Missing Authorization vulnerability in webraketen Internal Links Manager seo-automated-link-building allows Exploiting I... |
| CVE-2025-24678 | MEDIUM | 6.5 | 0.3% | Jan 24, 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in listamester Listamester l... |
| CVE-2025-24675 | MEDIUM | 6.5 | 0.3% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visit... |
| CVE-2025-24674 | MEDIUM | 5.9 | 0.3% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Denis Cherniatev S... |
| CVE-2025-24673 | MEDIUM | 6.5 | 0.3% | Jan 24, 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in AyeCode Ketchup Shortcode... |
| CVE-2025-24668 | MEDIUM | 5.9 | 0.3% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle PPOM for... |
| CVE-2025-24666 | MEDIUM | 5.9 | 0.3% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle AI Chatb... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now