2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-64052MEDIUM5.1An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to execute arb...
CVE-2025-14089MEDIUM6.3A vulnerability was identified in Himool ERP up to 2.2. Affected by this issue is the function update_account of the fil...
CVE-2025-14088MEDIUM6.3A vulnerability was determined in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is an unknown functionality of...
CVE-2025-6966MEDIUM5.5NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause ...
CVE-2025-66200MEDIUM5.4mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the R...
CVE-2025-65082MEDIUM6.5Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment va...
CVE-2025-13620MEDIUM5.3The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions ...
CVE-2025-13739MEDIUM6.4The CryptX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `cryptx` shortcode in all ...
CVE-2025-13682MEDIUM4.4The Trail Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u...
CVE-2025-13678MEDIUM6.4The Thai Lottery Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `thailottery` shortcod...
CVE-2025-12876MEDIUM5.3The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data d...
CVE-2025-13684MEDIUM4.3The ARK Related Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 2.19. This is due to m...
CVE-2025-12130MEDIUM4.3The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to...
CVE-2025-13515MEDIUM6.1The Nouri.sh Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF...
CVE-2025-12373MEDIUM4.3The Torod – The smart shipping and delivery portal for e-shops and retailers plugin for WordPress is vulnerable to Cross...
CVE-2025-12355MEDIUM5.3The Payaza plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on ...
CVE-2025-12354MEDIUM4.3The Live CSS Preview plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2025-12186MEDIUM4.4The Weekly Planner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions ...
CVE-2025-12093MEDIUM5.3The Voidek Employee Portal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o...
CVE-2025-66270MEDIUM4.7The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect ...
CVE-2025-32900MEDIUM4.3In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the di...
CVE-2025-13860MEDIUM6.4The Easy Jump Links Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `h_tags` parameter i...
CVE-2025-13625MEDIUM6.1The WP-SOS-Donate Donation Sidebar Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVE...
CVE-2025-13623MEDIUM6.1The Twitscription plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO in al...
CVE-2025-13622MEDIUM6.1The Jabbernotification plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now