2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12684 | HIGH | 7.1 | 0.1% | Dec 15, 2025 | The URL Shortify WordPress plugin before 1.11.3 does not sanitize and escape a parameter before outputting it back in t... |
| CVE-2025-67900 | HIGH | 8.1 | 0.1% | Dec 14, 2025 | NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable. |
| CVE-2025-14656 | HIGH | 8.8 | 0.6% | Dec 14, 2025 | A weakness has been identified in Tenda AC20 16.03.08.12. This affects the function httpd of the file /goform/openSchedW... |
| CVE-2025-14655 | HIGH | 8.8 | 2.9% | Dec 14, 2025 | A security flaw has been discovered in Tenda AC20 16.03.08.12. The impacted element is the function formSetRebootTimer o... |
| CVE-2025-14654 | HIGH | 8.8 | 2.9% | Dec 14, 2025 | A vulnerability was identified in Tenda AC20 16.03.08.12. The affected element is the function formSetPPTPUserList of th... |
| CVE-2025-14648 | HIGH | 7.2 | 6.5% | Dec 14, 2025 | A security vulnerability has been detected in DedeBIZ up to 6.5.9. Affected by this vulnerability is an unknown function... |
| CVE-2025-13126 | HIGH | 7.5 | 0.3% | Dec 14, 2025 | The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parame... |
| CVE-2025-14642 | HIGH | 7.2 | 0.3% | Dec 14, 2025 | A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the f... |
| CVE-2025-14641 | HIGH | 7.2 | 0.3% | Dec 14, 2025 | A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the... |
| CVE-2025-14589 | HIGH | 8.8 | 0.3% | Dec 13, 2025 | A weakness has been identified in code-projects Prison Management System 2.0. This issue affects some unknown processing... |
| CVE-2025-14542 | HIGH | 7.5 | 0.2% | Dec 13, 2025 | The vulnerability arises when a client fetches a tools’ JSON specification, known as a Manual, from a remote Manual Endp... |
| CVE-2025-14476 | HIGH | 8.8 | 0.5% | Dec 13, 2025 | The Doubly – Cross Domain Copy Paste for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all ver... |
| CVE-2025-14475 | HIGH | 8.1 | 0.5% | Dec 13, 2025 | The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in all vers... |
| CVE-2025-14397 | HIGH | 8.8 | 0.2% | Dec 13, 2025 | The Postem Ipsum plugin for WordPress is vulnerable to unauthorized modification of data to Privilege Escalation due to ... |
| CVE-2025-13094 | HIGH | 8.8 | 0.4% | Dec 13, 2025 | The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid... |
| CVE-2025-13089 | HIGH | 7.5 | 0.3% | Dec 13, 2025 | The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'hide_fields' and the 'attr_search' par... |
| CVE-2025-13077 | HIGH | 7.5 | 0.4% | Dec 13, 2025 | The افزونه پیامک ووکامرس فوق حرفه ای (جدید) payamito sms woocommerce plugin for WordPress is vulnerable to time-based bl... |
| CVE-2025-13970 | HIGH | 8 | 0.3% | Dec 13, 2025 | OpenPLC_V3 is vulnerable to a cross-site request forgery (CSRF) attack due to the absence of proper CSRF validation. Th... |
| CVE-2025-67721 | HIGH | 7.5 | 0.4% | Dec 12, 2025 | Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to Java. In versions... |
| CVE-2025-14582 | HIGH | 7.2 | 0.3% | Dec 12, 2025 | A vulnerability was detected in campcodes Online Student Enrollment System 1.0. This affects an unknown function of the ... |
| CVE-2025-67750 | HIGH | 8.4 | 0.2% | Dec 12, 2025 | Lightning Flow Scanner provides a A CLI plugin, VS Code Extension and GitHub Action for analysis and optimization of Sal... |
| CVE-2025-46285 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | An integer overflow was addressed by adopting 64-bit timestamps. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iO... |
| CVE-2025-43542 | HIGH | 7.5 | 0.8% | Dec 12, 2025 | This issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 a... |
| CVE-2025-43539 | HIGH | 8.8 | 5.7% | Dec 12, 2025 | The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and i... |
| CVE-2025-43527 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now