2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66169MEDIUM5.3Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 befo...
CVE-2025-66005HIGH8.5Lack of authorization of the InputManager D-Bus interface in InputPlumber versions before v0.63.0 can lead to local Deni...
CVE-2025-14338HIGH8.5Polkit authentication dis isabled by default and a race condition in the Polkit authorization check in versions before v...
CVE-2025-0647HIGH7.9In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a ...
CVE-2025-68492MEDIUM4.2Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vuln...
CVE-2025-15513MEDIUM5.3The Float Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to improper error ...
CVE-2025-15512MEDIUM5.3The Aplazo Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa...
CVE-2025-15475MEDIUM5.3The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of da...
CVE-2025-15376MEDIUM4.3The Stopwords for comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2025-14846MEDIUM4.3The SocialChamp with WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2025-14770HIGH7.5The Shipping Rate By Cities plugin for WordPress is vulnerable to SQL Injection via the 'city' parameter in all versions...
CVE-2025-14173MEDIUM5.3The Perfit WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,...
CVE-2025-15486MEDIUM4.4The Kunze Law plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's shortcode in all versions u...
CVE-2025-15378HIGH7.2The AJS Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'note_list_class' and 'popup...
CVE-2025-15377MEDIUM4.3The Sosh Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2025-15283HIGH7.2The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' and ...
CVE-2025-15266HIGH7.2The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to Sto...
CVE-2025-15021MEDIUM4.4The Gotham Block Extra Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all...
CVE-2025-15020MEDIUM6.5The Gotham Block Extra Light plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and includ...
CVE-2025-14880MEDIUM5.3The Netcash WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a...
CVE-2025-14854MEDIUM5.4The WP-CRM System plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on the wpcr...
CVE-2025-14725MEDIUM4.4The Internal Link Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve...
CVE-2025-14615HIGH7.1The DASHBOARD BUILDER – WordPress plugin for Charts and Graphs plugin for WordPress is vulnerable to Cross-Site Request ...
CVE-2025-14613HIGH7.2The GetContentFromURL plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu...
CVE-2025-14502CRITICAL9.8The News and Blog Designer Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now