2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-69194CRITICAL9.8A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validat...
CVE-2025-14937HIGH7.2The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acff' parame...
CVE-2025-14741CRITICAL9.1The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modifi...
CVE-2025-14657HIGH7.2The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unau...
CVE-2025-14146MEDIUM5.3The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc...
CVE-2025-13935MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course completio...
CVE-2025-13934MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course enrollmen...
CVE-2025-13753MEDIUM4.3The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2025-13628MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification and...
CVE-2025-70974CRITICAL10Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key i...
CVE-2025-15057HIGH7.2The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fh` (fingerprint) para...
CVE-2025-15055HIGH7.2The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' and 'resource' ...
CVE-2025-15019MEDIUM6.4The BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce plugin for WordPress is vulnerabl...
CVE-2025-14980MEDIUM6.5The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including...
CVE-2025-14893MEDIUM6.4The IndieWeb plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Telephone' parameter in all vers...
CVE-2025-14782MEDIUM5.3The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to authorizat...
CVE-2025-14736CRITICAL9.8The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i...
CVE-2025-14720MEDIUM5.3The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due ...
CVE-2025-14718MEDIUM5.4The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to authorization bypass in all ver...
CVE-2025-14574MEDIUM5.3The weDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2....
CVE-2025-14803MEDIUM6.8The NEX-Forms WordPress plugin before 9.1.8 does not sanitise and escape some of its settings. The NEX-Forms WordPress...
CVE-2025-13749MEDIUM4.3The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cr...
CVE-2025-14886MEDIUM5.3The Japanized for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...
CVE-2025-66315HIGH8.8There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper director...
CVE-2025-14436HIGH7.2The Brevo for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_connection_id’...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now