2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14744 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, poten... |
| CVE-2025-65000 | MEDIUM | 5.3 | 0.2% | Dec 18, 2025 | SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2... |
| CVE-2025-40893 | MEDIUM | 6.1 | 0.2% | Dec 18, 2025 | A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of netwo... |
| CVE-2025-40891 | MEDIUM | 4.7 | 0.1% | Dec 18, 2025 | A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper val... |
| CVE-2025-14618 | MEDIUM | 4.3 | 0.2% | Dec 18, 2025 | The Sweet Energy Efficiency plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data du... |
| CVE-2025-14277 | MEDIUM | 4.3 | 0.3% | Dec 18, 2025 | The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all version... |
| CVE-2025-13110 | MEDIUM | 4.3 | 0.3% | Dec 18, 2025 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Re... |
| CVE-2025-40602 | MEDIUM | 6.6 | 1.9% | Dec 18, 2025 | A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance manageme... |
| CVE-2025-64997 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Insufficient permission validation in Checkmk versions prior to 2.4.0p17 and 2.3.0p42 allow low-privileged users to view... |
| CVE-2025-13730 | MEDIUM | 6.4 | 0.2% | Dec 18, 2025 | The OpenID Connect Generic Client plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'op... |
| CVE-2025-67546 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs WP ERP erp allows Ret... |
| CVE-2025-66104 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in Anton Vanyukov Offload, AI & Optimize with Cloudflare Images cf-images allows Exp... |
| CVE-2025-66100 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in Magnigenie RestroPress restropress allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-66068 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured ... |
| CVE-2025-64375 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in Mahmudul Hasan Arif WP Social Ninja wp-social-reviews allows Exploiting Incorrect... |
| CVE-2025-64295 | MEDIUM | 6.5 | 0.3% | Dec 18, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi All In One SEO Pack all-in-one-seo-pack a... |
| CVE-2025-64273 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in GetResponse Email marketing for WordPress by GetResponse Official getresponse-off... |
| CVE-2025-64272 | MEDIUM | 6.5 | 0.3% | Dec 18, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in GetResponse Email marketing ... |
| CVE-2025-64270 | MEDIUM | 6.5 | 0.3% | Dec 18, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in masteriyo Masteriyo - LMS le... |
| CVE-2025-64225 | MEDIUM | 6.5 | 0.3% | Dec 18, 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in colabrio Stockie Extra st... |
| CVE-2025-64192 | MEDIUM | 6.3 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in 8theme XStore xstore allows Exploiting Incorrectly Configured Access Control Secu... |
| CVE-2025-63039 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in CridioStudio ListingPro listingpro allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-60088 | MEDIUM | 6.5 | 0.3% | Dec 18, 2025 | Missing Authorization vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Exploiting Incor... |
| CVE-2025-60070 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in The4 Molla molla allows Code Injection.This i... |
| CVE-2025-60068 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in javothemes Javo Core javo-core allows Code In... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now