2025 CVE Vulnerabilities

45,254 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-8062MEDIUM6.4The WS Theme Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ws_weather shortc...
CVE-2025-7957MEDIUM6.4The ShortcodeHub plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_link_target’ paramete...
CVE-2025-7842MEDIUM4.3The Silencesoft RSS Reader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2025-7841MEDIUM4.3The Sertifier Certificate & Badge Maker for WordPress – Tutor LMS plugin for WordPress is vulnerable to Cross-Site Reque...
CVE-2025-7839MEDIUM4.3The Restore Permanently delete Post or Page Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
CVE-2025-7828MEDIUM4.3The WP Filter & Combine RSS Feeds plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2025-7827MEDIUM4.3The Ni WooCommerce Customer Product Report plugin for WordPress is vulnerable to unauthorized modification of data due t...
CVE-2025-7821MEDIUM5.3The WC Plus plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2025-7642CRITICAL9.8The Simpler Checkout plugin for WordPress is vulnerable to Authentication Bypass in versions 0.7.0 to 1.1.9. This is due...
CVE-2025-43766CRITICAL9.8The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2...
CVE-2025-43765MEDIUM6.1A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0, 20...
CVE-2025-43764MEDIUM6.5Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScrip...
CVE-2025-43767MEDIUM6.1Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.86 through 7.4.3.131,...
CVE-2025-58043Rejected reason: Not used
CVE-2025-58042Rejected reason: Not used
CVE-2025-58041Rejected reason: Not used
CVE-2025-58040Rejected reason: Not used
CVE-2025-58039Rejected reason: Not used
CVE-2025-58038Rejected reason: Not used
CVE-2025-58037Rejected reason: Not used
CVE-2025-58036Rejected reason: Not used
CVE-2025-58035Rejected reason: Not used
CVE-2025-43769MEDIUM6.1Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q3.1 thr...
CVE-2025-43768HIGH7.7Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024....
CVE-2025-24469Rejected reason: Not used

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now