2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34179 | HIGH | 8.7 | 0.3% | Dec 15, 2025 | NetSupport Manager < 14.12.0001 contains an unauthenticated SQL injection vulnerability in its Connectivity Server/Gatew... |
| CVE-2025-14383 | HIGH | 7.5 | 0.4% | Dec 15, 2025 | The Booking Calendar plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'dates_to_check' param... |
| CVE-2025-65781 | HIGH | 8.2 | 0.3% | Dec 15, 2025 | An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upl... |
| CVE-2025-65780 | HIGH | 8.8 | 0.3% | Dec 15, 2025 | An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated ... |
| CVE-2025-65779 | HIGH | 7.5 | 0.3% | Dec 15, 2025 | An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticate... |
| CVE-2025-65778 | HIGH | 8.1 | 0.3% | Dec 15, 2025 | An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attac... |
| CVE-2025-37731 | HIGH | 7.4 | 0.2% | Dec 15, 2025 | Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica... |
| CVE-2025-14708 | HIGH | 7.5 | 6.5% | Dec 15, 2025 | A weakness has been identified in Shiguangwu sgwbox N3 2.0.25. Affected by this vulnerability is an unknown functionalit... |
| CVE-2025-14712 | HIGH | 8.7 | 0.3% | Dec 15, 2025 | Student Learning Assessment and Support System developed by JHENG GAO has a Exposure of Sensitive Information vulnerabil... |
| CVE-2025-14549 | HIGH | 8.1 | 0.3% | Dec 15, 2025 | In the Eclipse OMR compiler component, since release 0.7.0, an optimization enabled for Eclipse OpenJ9 consumers of OMR ... |
| CVE-2025-13355 | HIGH | 7.1 | 0.1% | Dec 15, 2025 | The URL Shortify WordPress plugin before 1.11.4 does not sanitise and escape a parameter before outputting it back in t... |
| CVE-2025-12684 | HIGH | 7.1 | 0.1% | Dec 15, 2025 | The URL Shortify WordPress plugin before 1.11.3 does not sanitize and escape a parameter before outputting it back in t... |
| CVE-2025-67900 | HIGH | 8.1 | 0.1% | Dec 14, 2025 | NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable. |
| CVE-2025-14656 | HIGH | 8.8 | 0.6% | Dec 14, 2025 | A weakness has been identified in Tenda AC20 16.03.08.12. This affects the function httpd of the file /goform/openSchedW... |
| CVE-2025-14655 | HIGH | 8.8 | 3.3% | Dec 14, 2025 | A security flaw has been discovered in Tenda AC20 16.03.08.12. The impacted element is the function formSetRebootTimer o... |
| CVE-2025-14654 | HIGH | 8.8 | 2.9% | Dec 14, 2025 | A vulnerability was identified in Tenda AC20 16.03.08.12. The affected element is the function formSetPPTPUserList of th... |
| CVE-2025-14648 | HIGH | 7.2 | 6.5% | Dec 14, 2025 | A security vulnerability has been detected in DedeBIZ up to 6.5.9. Affected by this vulnerability is an unknown function... |
| CVE-2025-13126 | HIGH | 7.5 | 0.3% | Dec 14, 2025 | The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parame... |
| CVE-2025-14642 | HIGH | 7.2 | 0.3% | Dec 14, 2025 | A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the f... |
| CVE-2025-14641 | HIGH | 7.2 | 0.3% | Dec 14, 2025 | A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the... |
| CVE-2025-14589 | HIGH | 8.8 | 0.3% | Dec 13, 2025 | A weakness has been identified in code-projects Prison Management System 2.0. This issue affects some unknown processing... |
| CVE-2025-14542 | HIGH | 7.5 | 0.2% | Dec 13, 2025 | The vulnerability arises when a client fetches a tools’ JSON specification, known as a Manual, from a remote Manual Endp... |
| CVE-2025-14476 | HIGH | 8.8 | 0.5% | Dec 13, 2025 | The Doubly – Cross Domain Copy Paste for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all ver... |
| CVE-2025-14475 | HIGH | 8.1 | 0.6% | Dec 13, 2025 | The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in all vers... |
| CVE-2025-14397 | HIGH | 8.8 | 0.2% | Dec 13, 2025 | The Postem Ipsum plugin for WordPress is vulnerable to unauthorized modification of data to Privilege Escalation due to ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now