2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66158 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Gmaper for Elementor gmaper-elementor allows Exploiting Incorrectly Con... |
| CVE-2025-66157 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Sliper for Elementor sliper-elementor allows Exploiting Incorrectly Con... |
| CVE-2025-66156 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Watcher for Elementor watcher-elementor allows Exploiting Incorrectly C... |
| CVE-2025-66155 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Questionar for Elementor questionar-elementor allows Exploiting Incorre... |
| CVE-2025-66154 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Couponer for Elementor couponer-elementor allows Exploiting Incorrectly... |
| CVE-2025-63038 | MEDIUM | 4.3 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface all... |
| CVE-2025-63021 | MEDIUM | 6.5 | 0.2% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codetipi Valenti E... |
| CVE-2025-62874 | MEDIUM | 4.3 | 0.3% | Dec 31, 2025 | Missing Authorization vulnerability in Alexander AnyComment anycomment allows Exploiting Incorrectly Configured Access C... |
| CVE-2025-62123 | MEDIUM | 4.3 | 0.1% | Dec 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in inkthemes WP Gmail SMTP wp-gmail-smtp allows Cross Site Request Forge... |
| CVE-2025-62115 | MEDIUM | 4.3 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in ThemeBoy Hide Plugins hide-plugins allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-62113 | MEDIUM | 4.3 | 0.1% | Dec 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in emendo_seb Co-marquage service-public.fr co-marquage-service-public a... |
| CVE-2025-62101 | MEDIUM | 4.3 | 0.1% | Dec 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Omid Shamloo Pardakht Delkhah pardakht-delkhah allows Cross Site Requ... |
| CVE-2025-62099 | MEDIUM | 4.3 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in approveme Signature Add-On for Gravity Forms gravity-signature-forms-add-on allow... |
| CVE-2025-62088 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Server-Side Request Forgery (SSRF) vulnerability in extendons WordPress & WooCommerce Scraper Plugin, Import Data from A... |
| CVE-2025-62083 | MEDIUM | 4.3 | 0.2% | Dec 31, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Messiah BoomDevs WordPres... |
| CVE-2025-62078 | MEDIUM | 4.3 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in Fahad Mahmood Easy Upload Files During Checkout easy-upload-files-during-checkout... |
| CVE-2025-59138 | MEDIUM | 4.9 | 0.2% | Dec 31, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Jthemes Genemy genemy allows Server Side Request Forgery.This issue ... |
| CVE-2025-49352 | MEDIUM | 4.3 | 0.2% | Dec 31, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in YoOhw Studio Order Cancellation & Returns for WooComme... |
| CVE-2025-49340 | MEDIUM | 4.3 | 0.3% | Dec 31, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Digages Direct Payments WP d... |
| CVE-2025-49339 | MEDIUM | 4.3 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in Digages Direct Payments WP direct-payments-wp allows Exploiting Incorrectly Confi... |
| CVE-2025-63040 | MEDIUM | 4.3 | 0.1% | Dec 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal Post Snippets post-snippets allows Cross Site Request Forg... |
| CVE-2025-63014 | MEDIUM | 4.3 | 0.1% | Dec 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Serhii Pasyuk Gmedia Photo Gallery grand-media allows Cross Site Requ... |
| CVE-2025-63004 | MEDIUM | 4.3 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in Skynet Technologies USA LLC All in One Accessibility all-in-one-accessibility all... |
| CVE-2025-62755 | MEDIUM | 5.3 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in GS Plugins GS Portfolio for Envato gs-envato-portfolio allows Exploiting Incorrec... |
| CVE-2025-62747 | MEDIUM | 5.3 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in Aum Watcharapon Featured Image Generator featured-image-generator allows Exploiti... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now