2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13215 | MEDIUM | 5.3 | 0.2% | Jan 6, 2026 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all vers... |
| CVE-2025-14441 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | The Popupkit plugin for WordPress is vulnerable to arbitrary subscriber data deletion due to missing authorization on th... |
| CVE-2025-14438 | MEDIUM | 6.4 | 0.2% | Jan 6, 2026 | The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, ... |
| CVE-2025-14120 | MEDIUM | 6.4 | 0.2% | Jan 6, 2026 | The URL Image Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver... |
| CVE-2025-14153 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | The Page Expire Popup/Redirection for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the '... |
| CVE-2025-14034 | MEDIUM | 5.3 | 0.2% | Jan 6, 2026 | The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of d... |
| CVE-2025-13746 | MEDIUM | 6.4 | 0.2% | Jan 6, 2026 | The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User's ... |
| CVE-2025-13652 | MEDIUM | 6.5 | 1.1% | Jan 6, 2026 | The CBX Bookmark & Favorite plugin for WordPress is vulnerable to generic SQL Injection via the ‘orderby’ parameter in a... |
| CVE-2025-13409 | MEDIUM | 4.9 | 0.3% | Jan 6, 2026 | The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to SQL Injection via the 'params' paramet... |
| CVE-2025-11723 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sen... |
| CVE-2025-11370 | MEDIUM | 5.3 | 0.2% | Jan 6, 2026 | The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel... |
| CVE-2025-20807 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In dpe, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privi... |
| CVE-2025-20806 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if... |
| CVE-2025-20805 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if... |
| CVE-2025-20804 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if... |
| CVE-2025-20803 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In dpe, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privile... |
| CVE-2025-20802 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privil... |
| CVE-2025-20794 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service... |
| CVE-2025-20793 | MEDIUM | 6.5 | 0.3% | Jan 6, 2026 | In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,... |
| CVE-2025-20787 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg... |
| CVE-2025-20786 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg... |
| CVE-2025-20785 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg... |
| CVE-2025-20784 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In display, there is a possible memory corruption due to uninitialized data. This could lead to local escalation of priv... |
| CVE-2025-20783 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o... |
| CVE-2025-20782 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now