2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14317HIGH7.1In Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enume...
CVE-2025-13175MEDIUM5.1Y Soft SafeQ 6 renders the Workflow Connector password field in a way that allows an administrator with UI access to rev...
CVE-2025-67859MEDIUM5.1A Improper Authentication vulnerability in TLP allows local users to arbitrarily control the power profile in use as wel...
CVE-2025-66169MEDIUM5.3Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 befo...
CVE-2025-66005HIGH8.5Lack of authorization of the InputManager D-Bus interface in InputPlumber versions before v0.63.0 can lead to local Deni...
CVE-2025-14338HIGH8.5Polkit authentication dis isabled by default and a race condition in the Polkit authorization check in versions before v...
CVE-2025-0647HIGH7.9In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a ...
CVE-2025-68492MEDIUM4.2Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vuln...
CVE-2025-15513MEDIUM5.3The Float Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to improper error ...
CVE-2025-15512MEDIUM5.3The Aplazo Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa...
CVE-2025-15475MEDIUM5.3The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of da...
CVE-2025-15376MEDIUM4.3The Stopwords for comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2025-14846MEDIUM4.3The SocialChamp with WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2025-14770HIGH7.5The Shipping Rate By Cities plugin for WordPress is vulnerable to SQL Injection via the 'city' parameter in all versions...
CVE-2025-14173MEDIUM5.3The Perfit WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,...
CVE-2025-15486MEDIUM4.4The Kunze Law plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's shortcode in all versions u...
CVE-2025-15378HIGH7.2The AJS Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'note_list_class' and 'popup...
CVE-2025-15377MEDIUM4.3The Sosh Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2025-15283HIGH7.2The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' and ...
CVE-2025-15266HIGH7.2The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to Sto...
CVE-2025-15021MEDIUM4.4The Gotham Block Extra Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all...
CVE-2025-15020MEDIUM6.5The Gotham Block Extra Light plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and includ...
CVE-2025-14880MEDIUM5.3The Netcash WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a...
CVE-2025-14854MEDIUM5.4The WP-CRM System plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on the wpcr...
CVE-2025-14725MEDIUM4.4The Internal Link Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now