2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66169 | MEDIUM | 5.3 | 0.6% | Jan 14, 2026 | Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 befo... |
| CVE-2025-66005 | HIGH | 8.5 | 0.2% | Jan 14, 2026 | Lack of authorization of the InputManager D-Bus interface in InputPlumber versions before v0.63.0 can lead to local Deni... |
| CVE-2025-14338 | HIGH | 8.5 | 0.2% | Jan 14, 2026 | Polkit authentication dis isabled by default and a race condition in the Polkit authorization check in versions before v... |
| CVE-2025-0647 | HIGH | 7.9 | 0.2% | Jan 14, 2026 | In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a ... |
| CVE-2025-68492 | MEDIUM | 4.2 | 0.2% | Jan 14, 2026 | Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vuln... |
| CVE-2025-15513 | MEDIUM | 5.3 | 0.2% | Jan 14, 2026 | The Float Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to improper error ... |
| CVE-2025-15512 | MEDIUM | 5.3 | 0.2% | Jan 14, 2026 | The Aplazo Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa... |
| CVE-2025-15475 | MEDIUM | 5.3 | 0.2% | Jan 14, 2026 | The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of da... |
| CVE-2025-15376 | MEDIUM | 4.3 | 0.1% | Jan 14, 2026 | The Stopwords for comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2025-14846 | MEDIUM | 4.3 | 0.1% | Jan 14, 2026 | The SocialChamp with WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a... |
| CVE-2025-14770 | HIGH | 7.5 | 0.3% | Jan 14, 2026 | The Shipping Rate By Cities plugin for WordPress is vulnerable to SQL Injection via the 'city' parameter in all versions... |
| CVE-2025-14173 | MEDIUM | 5.3 | 0.2% | Jan 14, 2026 | The Perfit WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,... |
| CVE-2025-15486 | MEDIUM | 4.4 | 0.2% | Jan 14, 2026 | The Kunze Law plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's shortcode in all versions u... |
| CVE-2025-15378 | HIGH | 7.2 | 0.3% | Jan 14, 2026 | The AJS Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'note_list_class' and 'popup... |
| CVE-2025-15377 | MEDIUM | 4.3 | 0.1% | Jan 14, 2026 | The Sosh Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2025-15283 | HIGH | 7.2 | 0.3% | Jan 14, 2026 | The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' and ... |
| CVE-2025-15266 | HIGH | 7.2 | 0.2% | Jan 14, 2026 | The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to Sto... |
| CVE-2025-15021 | MEDIUM | 4.4 | 0.2% | Jan 14, 2026 | The Gotham Block Extra Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all... |
| CVE-2025-15020 | MEDIUM | 6.5 | 0.3% | Jan 14, 2026 | The Gotham Block Extra Light plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and includ... |
| CVE-2025-14880 | MEDIUM | 5.3 | 0.2% | Jan 14, 2026 | The Netcash WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a... |
| CVE-2025-14854 | MEDIUM | 5.4 | 0.2% | Jan 14, 2026 | The WP-CRM System plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on the wpcr... |
| CVE-2025-14725 | MEDIUM | 4.4 | 0.2% | Jan 14, 2026 | The Internal Link Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve... |
| CVE-2025-14615 | HIGH | 7.1 | 0.1% | Jan 14, 2026 | The DASHBOARD BUILDER – WordPress plugin for Charts and Graphs plugin for WordPress is vulnerable to Cross-Site Request ... |
| CVE-2025-14613 | HIGH | 7.2 | 0.3% | Jan 14, 2026 | The GetContentFromURL plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu... |
| CVE-2025-14502 | CRITICAL | 9.8 | 1.3% | Jan 14, 2026 | The News and Blog Designer Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now