2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13629 | MEDIUM | 4.3 | 0.1% | Dec 6, 2025 | The WP Landing Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2025-13626 | MEDIUM | 6.1 | 0.2% | Dec 6, 2025 | The myLCO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter ... |
| CVE-2025-13358 | MEDIUM | 5.3 | 0.2% | Dec 6, 2025 | The Accessiy By CodeConfig Accessibility plugin for WordPress is vulnerable to unauthorized page creation due to missing... |
| CVE-2025-13309 | MEDIUM | 4.3 | 0.2% | Dec 6, 2025 | The Accessiy By CodeConfig Accessibility – Easy One-Click Accessibility Toolbar That Truly Matters plugin for WordPress ... |
| CVE-2025-13308 | MEDIUM | 5.4 | 0.2% | Dec 6, 2025 | The Application Passwords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'reject_url' para... |
| CVE-2025-13137 | MEDIUM | 6.1 | 0.2% | Dec 6, 2025 | The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to Reflected Cross-Site Script... |
| CVE-2025-12721 | MEDIUM | 5.3 | 0.2% | Dec 6, 2025 | The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2025-12720 | MEDIUM | 5.3 | 0.2% | Dec 6, 2025 | The g-FFL Cockpit plugin for WordPress is vulnerable to unauthorized modification of data due to IP-based authorization ... |
| CVE-2025-12717 | MEDIUM | 6.4 | 0.2% | Dec 6, 2025 | The List Attachments Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_list' p... |
| CVE-2025-12715 | MEDIUM | 6.4 | 0.2% | Dec 6, 2025 | The Canadian Nutrition Facts Label plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'percentage... |
| CVE-2025-12577 | MEDIUM | 4.3 | 0.2% | Dec 6, 2025 | The Listar – Directory Listing & Classifieds WordPress Plugin plugin for WordPress is vulnerable to unauthorized modific... |
| CVE-2025-12574 | MEDIUM | 4.3 | 0.2% | Dec 6, 2025 | The Listar – Directory Listing & Classifieds WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of... |
| CVE-2025-12091 | MEDIUM | 4.3 | 0.2% | Dec 6, 2025 | The Search, Filters & Merchandising for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of d... |
| CVE-2025-13922 | MEDIUM | 6.5 | 0.3% | Dec 6, 2025 | The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based bli... |
| CVE-2025-12505 | MEDIUM | 5.4 | 0.2% | Dec 6, 2025 | The weDocs plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.1.14. This ... |
| CVE-2025-11263 | MEDIUM | 6.1 | 0.2% | Dec 6, 2025 | The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the type parameter in all... |
| CVE-2025-66629 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.4, some of HedgeDoc's OA... |
| CVE-2025-14116 | MEDIUM | 4.7 | 0.2% | Dec 5, 2025 | A vulnerability was detected in xerrors Yuxi-Know up to 0.4.0. This vulnerability affects the function OtherEmbedding.ae... |
| CVE-2025-8148 | MEDIUM | 4.2 | 0.1% | Dec 5, 2025 | An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with a... |
| CVE-2025-14105 | MEDIUM | 4.3 | 0.3% | Dec 5, 2025 | A vulnerability was determined in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. This impacts an unknown function of the ... |
| CVE-2025-66581 | MEDIUM | 6.5 | 0.2% | Dec 5, 2025 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.41.0, ... |
| CVE-2025-66577 | MEDIUM | 5.3 | 0.2% | Dec 5, 2025 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allow... |
| CVE-2025-66558 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | Nextcloud Twofactor WebAuthn is the WebAuthn Two-Factor Provider for Nextcloud. Prior to 1.4.2 and 2.4.1, a missing owne... |
| CVE-2025-66557 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integra... |
| CVE-2025-66556 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | Nextcloud talk is a video & audio conferencing app for Nextcloud. Prior to 20.1.8 and 21.1.2, a participant with chat pe... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now