2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64052 | MEDIUM | 5.1 | 2.9% | Dec 5, 2025 | An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to execute arb... |
| CVE-2025-14089 | MEDIUM | 6.3 | 0.2% | Dec 5, 2025 | A vulnerability was identified in Himool ERP up to 2.2. Affected by this issue is the function update_account of the fil... |
| CVE-2025-14088 | MEDIUM | 6.3 | 0.2% | Dec 5, 2025 | A vulnerability was determined in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is an unknown functionality of... |
| CVE-2025-6966 | MEDIUM | 5.5 | 0.1% | Dec 5, 2025 | NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause ... |
| CVE-2025-66200 | MEDIUM | 5.4 | 0.6% | Dec 5, 2025 | mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the R... |
| CVE-2025-65082 | MEDIUM | 6.5 | 0.8% | Dec 5, 2025 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment va... |
| CVE-2025-13620 | MEDIUM | 5.3 | 0.3% | Dec 5, 2025 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions ... |
| CVE-2025-13739 | MEDIUM | 6.4 | 0.3% | Dec 5, 2025 | The CryptX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `cryptx` shortcode in all ... |
| CVE-2025-13682 | MEDIUM | 4.4 | 0.2% | Dec 5, 2025 | The Trail Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u... |
| CVE-2025-13678 | MEDIUM | 6.4 | 0.2% | Dec 5, 2025 | The Thai Lottery Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `thailottery` shortcod... |
| CVE-2025-12876 | MEDIUM | 5.3 | 0.3% | Dec 5, 2025 | The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data d... |
| CVE-2025-13684 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The ARK Related Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 2.19. This is due to m... |
| CVE-2025-12130 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to... |
| CVE-2025-13515 | MEDIUM | 6.1 | 0.2% | Dec 5, 2025 | The Nouri.sh Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF... |
| CVE-2025-12373 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The Torod – The smart shipping and delivery portal for e-shops and retailers plugin for WordPress is vulnerable to Cross... |
| CVE-2025-12355 | MEDIUM | 5.3 | 0.2% | Dec 5, 2025 | The Payaza plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on ... |
| CVE-2025-12354 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | The Live CSS Preview plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2025-12186 | MEDIUM | 4.4 | 0.2% | Dec 5, 2025 | The Weekly Planner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions ... |
| CVE-2025-12093 | MEDIUM | 5.3 | 0.2% | Dec 5, 2025 | The Voidek Employee Portal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o... |
| CVE-2025-66270 | MEDIUM | 4.7 | 0.2% | Dec 5, 2025 | The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect ... |
| CVE-2025-32900 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the di... |
| CVE-2025-13860 | MEDIUM | 6.4 | 0.2% | Dec 5, 2025 | The Easy Jump Links Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `h_tags` parameter i... |
| CVE-2025-13625 | MEDIUM | 6.1 | 0.2% | Dec 5, 2025 | The WP-SOS-Donate Donation Sidebar Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVE... |
| CVE-2025-13623 | MEDIUM | 6.1 | 0.2% | Dec 5, 2025 | The Twitscription plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO in al... |
| CVE-2025-13622 | MEDIUM | 6.1 | 0.2% | Dec 5, 2025 | The Jabbernotification plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now