2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36746 | MEDIUM | 5.4 | 0.1% | Dec 12, 2025 | SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject pay... |
| CVE-2025-36743 | MEDIUM | 6.8 | 0.2% | Dec 12, 2025 | SolarEdge SE3680H has an exposed debug/test interface accessible to unauthenticated actors, allowing disclosure of syste... |
| CVE-2025-14442 | MEDIUM | 5.3 | 0.3% | Dec 12, 2025 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to sensitive information expos... |
| CVE-2025-14159 | MEDIUM | 4.3 | 0.1% | Dec 12, 2025 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Cross-Site Request Forgery ... |
| CVE-2025-14065 | MEDIUM | 4.3 | 0.2% | Dec 12, 2025 | The Simple Bike Rental plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability che... |
| CVE-2025-14030 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The AI Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aife_post_meta' shortcode in all... |
| CVE-2025-12965 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Magical Posts Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mpac_title_tag' par... |
| CVE-2025-12408 | MEDIUM | 5.3 | 0.3% | Dec 12, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure i... |
| CVE-2025-12407 | MEDIUM | 4.3 | 0.1% | Dec 12, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request For... |
| CVE-2025-12841 | MEDIUM | 5.3 | 0.7% | Dec 12, 2025 | The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of t... |
| CVE-2025-23408 | MEDIUM | 6.5 | 0.4% | Dec 12, 2025 | Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.10.1. The is... |
| CVE-2025-14074 | MEDIUM | 4.3 | 0.2% | Dec 12, 2025 | The PDF for Contact Form 7 + Drag and Drop Template Builder plugin for WordPress is vulnerable to unauthorized post dupl... |
| CVE-2025-13993 | MEDIUM | 5.5 | 0.3% | Dec 12, 2025 | The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form... |
| CVE-2025-12348 | MEDIUM | 5.3 | 0.4% | Dec 12, 2025 | The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Miss... |
| CVE-2025-12960 | MEDIUM | 6.5 | 0.6% | Dec 12, 2025 | The Simple CSV Table plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0... |
| CVE-2025-67730 | MEDIUM | 5.4 | 0.1% | Dec 12, 2025 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to... |
| CVE-2025-4970 | MEDIUM | 5.5 | 0.3% | Dec 12, 2025 | The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio... |
| CVE-2025-14049 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | The VikRentItems Flexible Rental Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ... |
| CVE-2025-13891 | MEDIUM | 6.5 | 0.4% | Dec 12, 2025 | The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up t... |
| CVE-2025-11876 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Mailgun Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mailgun_su... |
| CVE-2025-14356 | MEDIUM | 4.3 | 0.3% | Dec 12, 2025 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing c... |
| CVE-2025-13660 | MEDIUM | 5.3 | 0.3% | Dec 12, 2025 | The Guest Support plugin for WordPress is vulnerable to User Email Disclosure in versions up to, and including, 1.2.3. T... |
| CVE-2025-12655 | MEDIUM | 5.3 | 0.2% | Dec 12, 2025 | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write via a missing authoriza... |
| CVE-2025-67724 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason ... |
| CVE-2025-10684 | MEDIUM | 4.3 | 0.1% | Dec 12, 2025 | The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX ac... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now