2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14657 | HIGH | 7.2 | 0.3% | Jan 9, 2026 | The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unau... |
| CVE-2025-14146 | MEDIUM | 5.3 | 0.3% | Jan 9, 2026 | The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc... |
| CVE-2025-13935 | MEDIUM | 4.3 | 0.2% | Jan 9, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course completio... |
| CVE-2025-13934 | MEDIUM | 4.3 | 0.2% | Jan 9, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course enrollmen... |
| CVE-2025-13753 | MEDIUM | 4.3 | 0.2% | Jan 9, 2026 | The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to unauthorized modification of data... |
| CVE-2025-13628 | MEDIUM | 4.3 | 0.2% | Jan 9, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification and... |
| CVE-2025-70974 | CRITICAL | 10 | 0.7% | Jan 9, 2026 | Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key i... |
| CVE-2025-15057 | HIGH | 7.2 | 0.2% | Jan 9, 2026 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fh` (fingerprint) para... |
| CVE-2025-15055 | HIGH | 7.2 | 0.2% | Jan 9, 2026 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' and 'resource' ... |
| CVE-2025-15019 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce plugin for WordPress is vulnerabl... |
| CVE-2025-14980 | MEDIUM | 6.5 | 0.3% | Jan 9, 2026 | The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including... |
| CVE-2025-14893 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The IndieWeb plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Telephone' parameter in all vers... |
| CVE-2025-14782 | MEDIUM | 5.3 | 0.3% | Jan 9, 2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to authorizat... |
| CVE-2025-14736 | CRITICAL | 9.8 | 0.7% | Jan 9, 2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i... |
| CVE-2025-14720 | MEDIUM | 5.3 | 0.3% | Jan 9, 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due ... |
| CVE-2025-14718 | MEDIUM | 5.4 | 0.3% | Jan 9, 2026 | The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to authorization bypass in all ver... |
| CVE-2025-14574 | MEDIUM | 5.3 | 0.3% | Jan 9, 2026 | The weDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.... |
| CVE-2025-14803 | MEDIUM | 6.8 | 0.2% | Jan 9, 2026 | The NEX-Forms WordPress plugin before 9.1.8 does not sanitise and escape some of its settings. The NEX-Forms WordPress... |
| CVE-2025-13749 | MEDIUM | 4.3 | 0.1% | Jan 9, 2026 | The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cr... |
| CVE-2025-14886 | MEDIUM | 5.3 | 0.2% | Jan 9, 2026 | The Japanized for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2025-66315 | HIGH | 8.8 | 0.2% | Jan 9, 2026 | There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper director... |
| CVE-2025-14436 | HIGH | 7.2 | 0.3% | Jan 8, 2026 | The Brevo for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_connection_id’... |
| CVE-2025-68719 | HIGH | 8.8 | 0.4% | Jan 8, 2026 | KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 mishandle configuration management. Once any user is logged in and main... |
| CVE-2025-68718 | MEDIUM | 5.4 | 0.3% | Jan 8, 2026 | KAYSUS KS-WR1200 routers with firmware 107 expose SSH and TELNET services on the LAN interface with hardcoded root crede... |
| CVE-2025-68717 | CRITICAL | 9.4 | 0.5% | Jan 8, 2026 | KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is l... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now