2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14657HIGH7.2The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unau...
CVE-2025-14146MEDIUM5.3The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc...
CVE-2025-13935MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course completio...
CVE-2025-13934MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course enrollmen...
CVE-2025-13753MEDIUM4.3The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2025-13628MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification and...
CVE-2025-70974CRITICAL10Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key i...
CVE-2025-15057HIGH7.2The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fh` (fingerprint) para...
CVE-2025-15055HIGH7.2The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' and 'resource' ...
CVE-2025-15019MEDIUM6.4The BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce plugin for WordPress is vulnerabl...
CVE-2025-14980MEDIUM6.5The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including...
CVE-2025-14893MEDIUM6.4The IndieWeb plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Telephone' parameter in all vers...
CVE-2025-14782MEDIUM5.3The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to authorizat...
CVE-2025-14736CRITICAL9.8The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i...
CVE-2025-14720MEDIUM5.3The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due ...
CVE-2025-14718MEDIUM5.4The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to authorization bypass in all ver...
CVE-2025-14574MEDIUM5.3The weDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2....
CVE-2025-14803MEDIUM6.8The NEX-Forms WordPress plugin before 9.1.8 does not sanitise and escape some of its settings. The NEX-Forms WordPress...
CVE-2025-13749MEDIUM4.3The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cr...
CVE-2025-14886MEDIUM5.3The Japanized for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...
CVE-2025-66315HIGH8.8There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper director...
CVE-2025-14436HIGH7.2The Brevo for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_connection_id’...
CVE-2025-68719HIGH8.8KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 mishandle configuration management. Once any user is logged in and main...
CVE-2025-68718MEDIUM5.4KAYSUS KS-WR1200 routers with firmware 107 expose SSH and TELNET services on the LAN interface with hardcoded root crede...
CVE-2025-68717CRITICAL9.4KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is l...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now