2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13418 | MEDIUM | 6.4 | 0.6% | Jan 7, 2026 | The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'plan_icons' para... |
| CVE-2025-13369 | MEDIUM | 6.1 | 0.3% | Jan 7, 2026 | The Premmerce WooCommerce Customers Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the... |
| CVE-2025-12648 | MEDIUM | 5.3 | 0.3% | Jan 7, 2026 | The WP-Members Membership Plugin for WordPress is vulnerable to unauthorized file access in versions up to, and includin... |
| CVE-2025-12540 | MEDIUM | 4.7 | 0.2% | Jan 7, 2026 | The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to Sensitive Information Exposure in all... |
| CVE-2025-12449 | MEDIUM | 5.4 | 0.2% | Jan 7, 2026 | The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and dis... |
| CVE-2025-12030 | MEDIUM | 4.3 | 0.3% | Jan 7, 2026 | The ACF to REST API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and in... |
| CVE-2025-0980 | MEDIUM | 6.4 | 0.1% | Jan 7, 2026 | Nokia SR Linux is vulnerable to an authentication vulnerability allowing unauthorized access to the JSON-RPC service. W... |
| CVE-2025-31051 | MEDIUM | 5.3 | 0.2% | Jan 7, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EngoTheme Plant - Gardening ... |
| CVE-2025-14612 | MEDIUM | 6.7 | 0.1% | Jan 7, 2026 | Insecure Temporary File vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows : Use of Predict... |
| CVE-2025-14605 | MEDIUM | 6.7 | 0.1% | Jan 7, 2026 | Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro on Windows (System Console modules) allows Se... |
| CVE-2025-14599 | MEDIUM | 6.7 | 0.1% | Jan 7, 2026 | Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard Installer (SFX) on Windows, Altera Qu... |
| CVE-2025-14596 | MEDIUM | 6.7 | 0.1% | Jan 7, 2026 | Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows Search ... |
| CVE-2025-13744 | MEDIUM | 5.4 | 0.2% | Jan 6, 2026 | An Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server ... |
| CVE-2025-7048 | MEDIUM | 5.3 | 0.2% | Jan 6, 2026 | On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec proc... |
| CVE-2025-69364 | MEDIUM | 5.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2025-69363 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in CyberChimps Responsive Addons for Elementor responsive-addons-for-elementor allow... |
| CVE-2025-69362 | MEDIUM | 5.9 | 0.1% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH UiChemy u... |
| CVE-2025-69361 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in PublishPress Post Expirator post-expirator allows Exploiting Incorrectly Configur... |
| CVE-2025-69360 | MEDIUM | 6.5 | 0.1% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem... |
| CVE-2025-69359 | MEDIUM | 5.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in WPFunnels Creator LMS creatorlms allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-69357 | MEDIUM | 6.5 | 0.1% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem... |
| CVE-2025-69355 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in Tickera Tickera tickera-event-ticketing-system allows Exploiting Incorrectly Conf... |
| CVE-2025-69354 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in BBR Plugins Better Business Reviews better-business-reviews allows Exploiting Inc... |
| CVE-2025-69353 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in Proxy & VPN Blocker Proxy & VPN Blocker proxy-vpn-blocker allows Exploiting Incor... |
| CVE-2025-69352 | MEDIUM | 5.4 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly C... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now