2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13220 | MEDIUM | 6.4 | 0.2% | Dec 21, 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi... |
| CVE-2025-12398 | MEDIUM | 6.1 | 0.2% | Dec 21, 2025 | The Product Table for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_k... |
| CVE-2025-14080 | MEDIUM | 5.3 | 0.2% | Dec 21, 2025 | The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Missing Authorization in all versions up... |
| CVE-2025-14054 | MEDIUM | 4.4 | 0.2% | Dec 21, 2025 | The WC Builder – WooCommerce Page Builder for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2025-14043 | MEDIUM | 5.3 | 0.3% | Dec 21, 2025 | The Tainacan plugin for WordPress is vulnerable to unauthorized metadata section creation due to missing authorization c... |
| CVE-2025-13838 | MEDIUM | 6.4 | 0.2% | Dec 21, 2025 | The WishSuite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter of the '... |
| CVE-2025-11496 | MEDIUM | 6.1 | 0.2% | Dec 21, 2025 | The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2025-7733 | MEDIUM | 4.3 | 0.2% | Dec 20, 2025 | The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Insecure Direct Object Reference in a... |
| CVE-2025-14298 | MEDIUM | 5.4 | 0.3% | Dec 20, 2025 | The FiboSearch – Ajax Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p... |
| CVE-2025-12492 | MEDIUM | 5.3 | 0.4% | Dec 20, 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi... |
| CVE-2025-12820 | MEDIUM | 5.3 | 0.2% | Dec 20, 2025 | The Pure WC Variation Swatches WordPress plugin through 1.1.7 does not have an authorization check when updating its set... |
| CVE-2025-14735 | MEDIUM | 4.4 | 0.2% | Dec 20, 2025 | The "Amazon affiliate lite Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings ... |
| CVE-2025-14734 | MEDIUM | 5.4 | 0.1% | Dec 20, 2025 | The Amazon affiliate lite Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2025-14721 | MEDIUM | 5.5 | 0.2% | Dec 20, 2025 | The Responsive and Swipe slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rsSli... |
| CVE-2025-14633 | MEDIUM | 5.3 | 0.2% | Dec 20, 2025 | The F70 Lead Document Download plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi... |
| CVE-2025-14168 | MEDIUM | 4.3 | 0.1% | Dec 20, 2025 | The WP DB Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-14164 | MEDIUM | 4.3 | 0.1% | Dec 20, 2025 | The Quran Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-13624 | MEDIUM | 6.1 | 0.2% | Dec 20, 2025 | The Overstock Affiliate Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PH... |
| CVE-2025-13365 | MEDIUM | 6.1 | 0.1% | Dec 20, 2025 | The WP Hallo Welt plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-12898 | MEDIUM | 5.3 | 0.2% | Dec 20, 2025 | The Pretty Google Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability... |
| CVE-2025-12581 | MEDIUM | 6.1 | 0.2% | Dec 20, 2025 | The Attachments Handler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up ... |
| CVE-2025-8065 | MEDIUM | 6.5 | 0.5% | Dec 20, 2025 | A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6.... |
| CVE-2025-14299 | MEDIUM | 6.5 | 0.2% | Dec 20, 2025 | The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer over... |
| CVE-2025-67712 | MEDIUM | 4.7 | 0.3% | Dec 19, 2025 | There is an HTML injection issue in Esri ArcGIS Web AppBuilder developer edition versions prior to 2.30 that allows a re... |
| CVE-2025-12874 | MEDIUM | 6.3 | 0.4% | Dec 19, 2025 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Quest Coexistence Mana... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now