2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-12684HIGH7.1The URL Shortify WordPress plugin before 1.11.3 does not sanitize and escape a parameter before outputting it back in t...
CVE-2025-67900HIGH8.1NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.
CVE-2025-14656HIGH8.8A weakness has been identified in Tenda AC20 16.03.08.12. This affects the function httpd of the file /goform/openSchedW...
CVE-2025-14655HIGH8.8A security flaw has been discovered in Tenda AC20 16.03.08.12. The impacted element is the function formSetRebootTimer o...
CVE-2025-14654HIGH8.8A vulnerability was identified in Tenda AC20 16.03.08.12. The affected element is the function formSetPPTPUserList of th...
CVE-2025-14648HIGH7.2A security vulnerability has been detected in DedeBIZ up to 6.5.9. Affected by this vulnerability is an unknown function...
CVE-2025-13126HIGH7.5The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parame...
CVE-2025-14642HIGH7.2A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the f...
CVE-2025-14641HIGH7.2A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the...
CVE-2025-14589HIGH8.8A weakness has been identified in code-projects Prison Management System 2.0. This issue affects some unknown processing...
CVE-2025-14542HIGH7.5The vulnerability arises when a client fetches a tools’ JSON specification, known as a Manual, from a remote Manual Endp...
CVE-2025-14476HIGH8.8The Doubly – Cross Domain Copy Paste for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all ver...
CVE-2025-14475HIGH8.1The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in all vers...
CVE-2025-14397HIGH8.8The Postem Ipsum plugin for WordPress is vulnerable to unauthorized modification of data to Privilege Escalation due to ...
CVE-2025-13094HIGH8.8The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid...
CVE-2025-13089HIGH7.5The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'hide_fields' and the 'attr_search' par...
CVE-2025-13077HIGH7.5The افزونه پیامک ووکامرس فوق حرفه ای (جدید) payamito sms woocommerce plugin for WordPress is vulnerable to time-based bl...
CVE-2025-13970HIGH8OpenPLC_V3 is vulnerable to a cross-site request forgery (CSRF) attack due to the absence of proper CSRF validation. Th...
CVE-2025-67721HIGH7.5Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to Java. In versions...
CVE-2025-14582HIGH7.2A vulnerability was detected in campcodes Online Student Enrollment System 1.0. This affects an unknown function of the ...
CVE-2025-67750HIGH8.4Lightning Flow Scanner provides a A CLI plugin, VS Code Extension and GitHub Action for analysis and optimization of Sal...
CVE-2025-46285HIGH7.8An integer overflow was addressed by adopting 64-bit timestamps. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iO...
CVE-2025-43542HIGH7.5This issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 a...
CVE-2025-43539HIGH8.8The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and i...
CVE-2025-43527HIGH7.8A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now