Skip to main content

Year archive

CVEs published in 2025

Archive summary

48,162 CVEs published in 2025 — 3,936 Critical, 15,187 High, 24,285 Medium, 3,397 Low, 1,357 Unrated.

CVE-2023-47807

Published Jan 2, 2025

Missing Authorization vulnerability in 10Web 10WebAnalytics wd-google-analytics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 10WebAna…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-47778

Published Jan 2, 2025

Missing Authorization vulnerability in LuckyWP LuckyWP Scripts Control luckywp-scripts-control allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-45633

Published Jan 2, 2025

Missing Authorization vulnerability in IDX IMPress Listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IMPress Listings: from n/a t…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-45272

Published Jan 2, 2025

Missing Authorization vulnerability in 10Web 10Web Map Builder for Google Maps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 10Web Map…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40327

Published Jan 2, 2025

Missing Authorization vulnerability in Putler / Storeapps Putler Connector for WooCommerce.This issue affects Putler Connector for WooCommerce: from n/a through 2.12.0.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-39994

Published Jan 2, 2025

Missing Authorization vulnerability in Repute InfoSystems ARMember Premium allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ARMember Prem…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-32240

Published Jan 2, 2025

Missing Authorization vulnerability in Xtemos WoodMart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WoodMart: from n/a through 7.2.1.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2022-49035

Published Jan 2, 2025

In the Linux kernel, the following vulnerability has been resolved: media: s5p_cec: limit msg.len to CEC_MAX_MSG_SIZE I expect that the hardware will have limited this to 16, bu…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43476

Published Jan 2, 2025

Missing Authorization vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category allows Exploiting Incorrectly Configured Access Control Security Levels.This…

CVSS 4.3 · Medium

CVE-2022-41995

Published Jan 2, 2025

Missing Authorization vulnerability in Galleryape Gallery Images Ape allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gallery Images Ape:…

CVSS 4.3 · Medium

CVE-2024-38732

Published Jan 2, 2025

Cross-Site Request Forgery (CSRF) vulnerability in VolThemes Patricia Blog allows Cross Site Request Forgery.This issue affects Patricia Blog: from n/a through 1.2.

CVSS 4.3 · Medium

CVE-2024-38731

Published Jan 2, 2025

Cross-Site Request Forgery (CSRF) vulnerability in Marsian i-amaze allows Cross Site Request Forgery.This issue affects i-amaze: from n/a through 1.3.7.

CVSS 4.3 · Medium

CVE-2024-37931

Published Jan 2, 2025

Cross-Site Request Forgery (CSRF) vulnerability in Creativthemes Point allows Cross Site Request Forgery.This issue affects Point: from n/a through 1.1.

CVSS 4.3 · Medium

CVE-2024-37925

Published Jan 2, 2025

Cross-Site Request Forgery (CSRF) vulnerability in BUDDYBOSS LLC BuddyBoss Theme allows Cross Site Request Forgery.This issue affects BuddyBoss Theme: from n/a through 2.4.61.

CVSS 5.4 · Medium

CVE-2024-37452

Published Jan 2, 2025

Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop Schema Lite allows Cross Site Request Forgery.This issue affects Schema Lite: from n/a through 1.2.2.

CVSS 4.3 · Medium

CVE-2024-37438

Published Jan 2, 2025

Cross-Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Toolkit Pro for LearnDash allows Cross Site Request Forgery.This issue affects Uncanny Toolkit Pro for Learn…

CVSS 5.4 · Medium

CVE-2024-37241

Published Jan 2, 2025

Cross-Site Request Forgery (CSRF) vulnerability in Automattic WP Job Manager - Resume Manager allows Cross Site Request Forgery.This issue affects WP Job Manager - Resume Manager:…

CVSS 4.3 · Medium

CVE-2024-37237

Published Jan 2, 2025

Cross-Site Request Forgery (CSRF) vulnerability in fs-code FS Poster fs-poster allows Cross Site Request Forgery.This issue affects FS Poster: from n/a through <= 6.5.8.

CVSS 4.3 · Medium

CVE-2024-56268

Published Jan 2, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hookandhook Post Grid Elementor Addon post-grid-elementor-addon.This issue af…

CVSS 6.5 · Medium

CVE-2024-56257

Published Jan 2, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CoolPlugins Coins MarketCap coins-marketcap allows DOM-Based XSS.This issue a…

CVSS 6.5 · Medium

CVE-2024-56014

Published Jan 2, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markyis Cool Olivia allows Reflected XSS.This issue affects Olivia: from n/a…

CVSS 7.1 · High

CVE-2024-39623

Published Jan 2, 2025

Cross-Site Request Forgery (CSRF) vulnerability in CridioStudio ListingPro listingpro allows Authentication Bypass.This issue affects ListingPro: from n/a through <= 2.9.4.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 47,951-47,975 of 48,162 CVEsPage 1919 of 1927