2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11991 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to unauthorized modification of data... |
| CVE-2025-62330 | MEDIUM | 5.9 | 0.1% | Dec 16, 2025 | HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains acce... |
| CVE-2025-13794 | MEDIUM | 4.3 | 0.3% | Dec 16, 2025 | The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized modification of data du... |
| CVE-2025-12809 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | The Dokan Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the... |
| CVE-2025-66357 | MEDIUM | 6.9 | 0.3% | Dec 16, 2025 | CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper check for unusual or exceptional conditions. When the... |
| CVE-2025-59479 | MEDIUM | 6.1 | 0.2% | Dec 16, 2025 | CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper restriction of rendered UI layers or frames. If a use... |
| CVE-2025-14777 | MEDIUM | 6 | 0.3% | Dec 16, 2025 | A flaw was found in Keycloak. An IDOR (Broken Access Control) vulnerability exists in the admin API endpoints for author... |
| CVE-2025-13956 | MEDIUM | 5.3 | 0.9% | Dec 16, 2025 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing... |
| CVE-2025-14748 | MEDIUM | 5.4 | 0.6% | Dec 16, 2025 | A vulnerability was determined in Ningyuanda TC155 57.0.2.0. This affects an unknown function of the file /onvif/device_... |
| CVE-2025-14747 | MEDIUM | 6.5 | 0.6% | Dec 16, 2025 | A vulnerability was found in Ningyuanda TC155 57.0.2.0. The impacted element is an unknown function of the component RTS... |
| CVE-2025-14746 | MEDIUM | 6.5 | 0.9% | Dec 16, 2025 | A vulnerability has been found in Ningyuanda TC155 57.0.2.0. The affected element is an unknown function of the componen... |
| CVE-2025-68115 | MEDIUM | 6.1 | 0.2% | Dec 16, 2025 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prio... |
| CVE-2025-68113 | MEDIUM | 6.5 | 0.3% | Dec 16, 2025 | ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA librari... |
| CVE-2025-67874 | MEDIUM | 6.5 | 0.3% | Dec 16, 2025 | ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext pass... |
| CVE-2025-67735 | MEDIUM | 6.5 | 0.3% | Dec 16, 2025 | Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final... |
| CVE-2025-67715 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification setti... |
| CVE-2025-67492 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for m... |
| CVE-2025-14758 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | Incorrect configuration of replication security in the MariaDB component of the infra-operator in YAOOK Operator allows ... |
| CVE-2025-66482 | MEDIUM | 6.5 | 0.3% | Dec 16, 2025 | Misskey is an open source, federated social media platform. Attackers who use an untrusted reverse proxy or not using a ... |
| CVE-2025-66407 | MEDIUM | 5 | 0.2% | Dec 16, 2025 | Weblate is a web based localization tool. The Create Component functionality in Weblate allows authorized users to add n... |
| CVE-2025-66402 | MEDIUM | 6.5 | 0.3% | Dec 16, 2025 | Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025... |
| CVE-2025-9122 | MEDIUM | 5.3 | 0.2% | Dec 15, 2025 | Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, includi... |
| CVE-2025-67809 | MEDIUM | 4.7 | 0.2% | Dec 15, 2025 | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present i... |
| CVE-2025-36360 | MEDIUM | 5 | 0.2% | Dec 15, 2025 | IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM De... |
| CVE-2025-14148 | MEDIUM | 6.5 | 0.3% | Dec 15, 2025 | IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration pri... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now