2025 CVE Vulnerabilities

45,322 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-54045MEDIUM4.3Missing Authorization vulnerability in CreativeMindsSolutions CM On Demand Search And Replace cm-on-demand-search-and-re...
CVE-2025-54005MEDIUM4.3Missing Authorization vulnerability in sonalsinha21 SKT Page Builder skt-builder allows Exploiting Incorrectly Configure...
CVE-2025-13231MEDIUM6.5The Fancy Product Designer plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and ...
CVE-2025-13439MEDIUM5.9The Fancy Product Designer plugin for WordPress is vulnerable to Information Disclosure and PHAR Deserialization in all ...
CVE-2025-11991MEDIUM5.3The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2025-62330MEDIUM5.9HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains acce...
CVE-2025-13794MEDIUM4.3The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized modification of data du...
CVE-2025-12809MEDIUM5.3The Dokan Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the...
CVE-2025-66357MEDIUM6.9CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper check for unusual or exceptional conditions. When the...
CVE-2025-59479MEDIUM6.1CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper restriction of rendered UI layers or frames. If a use...
CVE-2025-14777MEDIUM6A flaw was found in Keycloak. An IDOR (Broken Access Control) vulnerability exists in the admin API endpoints for author...
CVE-2025-13956MEDIUM5.3The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing...
CVE-2025-14748MEDIUM5.4A vulnerability was determined in Ningyuanda TC155 57.0.2.0. This affects an unknown function of the file /onvif/device_...
CVE-2025-14747MEDIUM6.5A vulnerability was found in Ningyuanda TC155 57.0.2.0. The impacted element is an unknown function of the component RTS...
CVE-2025-14746MEDIUM6.5A vulnerability has been found in Ningyuanda TC155 57.0.2.0. The affected element is an unknown function of the componen...
CVE-2025-68115MEDIUM6.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prio...
CVE-2025-68113MEDIUM6.5ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA librari...
CVE-2025-67874MEDIUM6.5ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext pass...
CVE-2025-67735MEDIUM6.5Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final...
CVE-2025-67715MEDIUM4.3Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification setti...
CVE-2025-67492MEDIUM5.3Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for m...
CVE-2025-14758MEDIUM6.5Incorrect configuration of replication security in the MariaDB component of the infra-operator in YAOOK Operator allows ...
CVE-2025-66482MEDIUM6.5Misskey is an open source, federated social media platform. Attackers who use an untrusted reverse proxy or not using a ...
CVE-2025-66407MEDIUM5Weblate is a web based localization tool. The Create Component functionality in Weblate allows authorized users to add n...
CVE-2025-66402MEDIUM6.5Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now