2025 CVE Vulnerabilities
45,139 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14760 | MEDIUM | 6 | 0.1% | Dec 17, 2025 | Missing cryptographic key commitment in the AWS SDK for C++ may allow a user with write access to the S3 bucket to intro... |
| CVE-2025-14759 | MEDIUM | 6 | 0.1% | Dec 17, 2025 | Missing cryptographic key commitment in the Amazon S3 Encryption Client for .NET may allow a user with write access to t... |
| CVE-2025-67173 | MEDIUM | 6.8 | 0.2% | Dec 17, 2025 | A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrar... |
| CVE-2025-67170 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the... |
| CVE-2025-67168 | MEDIUM | 5.3 | 0.1% | Dec 17, 2025 | RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords. |
| CVE-2025-14081 | MEDIUM | 4.3 | 0.3% | Dec 17, 2025 | The Ultimate Member plugin for WordPress is vulnerable to Profile Privacy Setting Bypass in all versions up to, and incl... |
| CVE-2025-13537 | MEDIUM | 6.4 | 0.2% | Dec 17, 2025 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to multiple Stored Cross-Site Scri... |
| CVE-2025-13217 | MEDIUM | 6.4 | 0.3% | Dec 17, 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for W... |
| CVE-2025-12689 | MEDIUM | 6.5 | 0.2% | Dec 17, 2025 | Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for p... |
| CVE-2025-66924 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remot... |
| CVE-2025-65855 | MEDIUM | 6.6 | 0.1% | Dec 17, 2025 | The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-... |
| CVE-2025-26381 | MEDIUM | 6.5 | 0.3% | Dec 17, 2025 | Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to sensitive informati... |
| CVE-2025-62690 | MEDIUM | 6.1 | 0.1% | Dec 17, 2025 | Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to re... |
| CVE-2025-62190 | MEDIUM | 4.3 | 0.1% | Dec 17, 2025 | Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail... |
| CVE-2025-14095 | MEDIUM | 6.8 | 0.1% | Dec 17, 2025 | A "Privilege boundary violation" vulnerability is identified affecting multiple Radiometer Products. Exploitation of thi... |
| CVE-2025-14347 | MEDIUM | 6.3 | 0.2% | Dec 17, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Soft... |
| CVE-2025-14399 | MEDIUM | 4.3 | 0.1% | Dec 17, 2025 | The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery i... |
| CVE-2025-12496 | MEDIUM | 4.9 | 0.6% | Dec 17, 2025 | The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includin... |
| CVE-2025-14817 | MEDIUM | 6.5 | 0.2% | Dec 17, 2025 | The component com.transsion.tranfacmode.entrance.main.MainActivity in com.transsion.tranfacmode has no permission contro... |
| CVE-2025-14061 | MEDIUM | 5.3 | 0.2% | Dec 17, 2025 | The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie C... |
| CVE-2025-13750 | MEDIUM | 4.3 | 0.2% | Dec 17, 2025 | The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modif... |
| CVE-2025-14154 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vu... |
| CVE-2025-64700 | MEDIUM | 5.1 | 0.1% | Dec 17, 2025 | Cross-site request forgery vulnerability exists in GROWI v7.3.3 and earlier. If a user views a malicious page while logg... |
| CVE-2025-14385 | MEDIUM | 6.4 | 0.3% | Dec 17, 2025 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all ve... |
| CVE-2025-13880 | MEDIUM | 6.5 | 0.2% | Dec 17, 2025 | The WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now