2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14208 | MEDIUM | 6.3 | 2.8% | Dec 8, 2025 | A security flaw has been discovered in D-Link DIR-823X up to 20250416. This affects the function sub_415028 of the file ... |
| CVE-2025-14205 | MEDIUM | 5.4 | 0.2% | Dec 8, 2025 | A vulnerability was found in code-projects Chamber of Commerce Membership Management System 1.0. Impacted is an unknown ... |
| CVE-2025-14204 | MEDIUM | 6.3 | 1.2% | Dec 7, 2025 | A vulnerability has been found in TykoDev cherry-studio-TykoFork 0.1. This issue affects the function redirectToAuthoriz... |
| CVE-2025-14201 | MEDIUM | 4.8 | 0.2% | Dec 7, 2025 | A vulnerability was found in alokjaiswal Hotel-Management-services-using-MYSQL-and-php up to 5f8b60a7aa6c06a5632de569d4e... |
| CVE-2025-14200 | MEDIUM | 6.1 | 0.2% | Dec 7, 2025 | A vulnerability has been found in alokjaiswal Hotel-Management-services-using-MYSQL-and-php up to 5f8b60a7aa6c06a5632de5... |
| CVE-2025-14198 | MEDIUM | 5.5 | 0.4% | Dec 7, 2025 | A vulnerability was detected in Verysync 微力同步 2.21.3. This affects an unknown function of the file /safebrowsing/clientr... |
| CVE-2025-14197 | MEDIUM | 5.5 | 0.3% | Dec 7, 2025 | A security vulnerability has been detected in Verysync 微力同步 up to 2.21.3. The impacted element is an unknown function of... |
| CVE-2025-14194 | MEDIUM | 5.4 | 0.2% | Dec 7, 2025 | A vulnerability was identified in code-projects Employee Profile Management System 1.0. This issue affects some unknown ... |
| CVE-2025-14185 | MEDIUM | 6.3 | 0.2% | Dec 7, 2025 | A vulnerability was identified in Yonyou U8 Cloud 5.0/5.0sp/5.1/5.1sp. The affected element is an unknown function of th... |
| CVE-2025-14184 | MEDIUM | 6.3 | 2.0% | Dec 7, 2025 | A vulnerability was determined in SGAI Space1 NAS N1211DS up to 1.0.915. Impacted is the function RENAME_FILE/OPERATE_FI... |
| CVE-2025-14183 | MEDIUM | 4.3 | 0.2% | Dec 7, 2025 | A vulnerability was found in SGAI Space1 NAS N1211DS up to 1.0.915. This issue affects the function GET_FACTORY_INFO/GET... |
| CVE-2025-14140 | MEDIUM | 6.5 | 0.5% | Dec 6, 2025 | A vulnerability was detected in UTT 进取 520W 1.7.7-180627. The affected element is the function strcpy of the file /gofor... |
| CVE-2025-14139 | MEDIUM | 5.7 | 1.0% | Dec 6, 2025 | A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Impacted is the function strcpy of the file /gof... |
| CVE-2025-13748 | MEDIUM | 5.3 | 0.3% | Dec 6, 2025 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne... |
| CVE-2025-14117 | MEDIUM | 6.5 | 0.2% | Dec 6, 2025 | A vulnerability has been found in fit2cloud Halo 2.21.10. Impacted is an unknown function. The manipulation leads to cro... |
| CVE-2025-13907 | MEDIUM | 6.4 | 0.2% | Dec 6, 2025 | The CSS3 Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode i... |
| CVE-2025-13899 | MEDIUM | 6.4 | 0.2% | Dec 6, 2025 | The TR Timthumb plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all versio... |
| CVE-2025-13898 | MEDIUM | 6.4 | 0.2% | Dec 6, 2025 | The Ultra Skype Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_id' parameter of t... |
| CVE-2025-13896 | MEDIUM | 6.4 | 0.2% | Dec 6, 2025 | The Social Feed Gallery Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' paramet... |
| CVE-2025-13894 | MEDIUM | 6.1 | 0.2% | Dec 6, 2025 | The CSV Sumotto plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` vari... |
| CVE-2025-13863 | MEDIUM | 6.4 | 0.2% | Dec 6, 2025 | The RevInsite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `token` parameter in all version... |
| CVE-2025-13857 | MEDIUM | 6.4 | 0.2% | Dec 6, 2025 | The Yet Another WebClap for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' p... |
| CVE-2025-13856 | MEDIUM | 6.4 | 0.2% | Dec 6, 2025 | The Extra Post Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the ex... |
| CVE-2025-13666 | MEDIUM | 5.3 | 0.2% | Dec 6, 2025 | The Helloprint plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.2. This... |
| CVE-2025-13656 | MEDIUM | 6.4 | 0.2% | Dec 6, 2025 | The Cute News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now