2025 CVE Vulnerabilities

45,168 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62901MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tormorten WP Micro...
CVE-2025-62955MEDIUM4.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HappyDevs TempTool [Show Cu...
CVE-2025-14995HIGH8.8A vulnerability has been found in Tenda FH1201 1.2.0.14(408). Affected is the function sprintf of the file /goform/SetIp...
CVE-2025-14994HIGH8.8A flaw has been found in Tenda FH1201 and FH1206 1.2.0.14(408)/1.2.0.8(8155). This impacts the function strcat of the fi...
CVE-2025-14855HIGH7.2The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all ver...
CVE-2025-14800HIGH8.1The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type...
CVE-2025-14993HIGH8.8A vulnerability was detected in Tenda AC18 15.03.05.05. This affects the function sprintf of the file /goform/SetDlnaCfg...
CVE-2025-9343HIGH7.2The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2025-68644HIGH7.4Yealink RPS before 2025-06-27 allows unauthorized access to information, including AutoP URL addresses. This was fixed b...
CVE-2025-14992HIGH8.8A security vulnerability has been detected in Tenda AC18 15.03.05.05. The impacted element is the function strcpy of the...
CVE-2025-14991MEDIUM4.8A weakness has been identified in Campcodes Complete Online Beauty Parlor Management System 1.0. The affected element is...
CVE-2025-14990CRITICAL9.8A security flaw has been discovered in Campcodes Complete Online Beauty Parlor Management System 1.0. Impacted is an unk...
CVE-2025-13693MEDIUM6.4The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Cust...
CVE-2025-13361MEDIUM4.3The Web to SugarCRM Lead plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2025-13220MEDIUM6.4The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2025-12654LOW2.7The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory cr...
CVE-2025-12398MEDIUM6.1The Product Table for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_k...
CVE-2025-14080MEDIUM5.3The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Missing Authorization in all versions up...
CVE-2025-14071HIGH7.5The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all ver...
CVE-2025-14054MEDIUM4.4The WC Builder – WooCommerce Page Builder for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2025-14043MEDIUM5.3The Tainacan plugin for WordPress is vulnerable to unauthorized metadata section creation due to missing authorization c...
CVE-2025-13838MEDIUM6.4The WishSuite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter of the '...
CVE-2025-12980HIGH7.5The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthor...
CVE-2025-11496MEDIUM6.1The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2025-14989CRITICAL9.8A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This issue affects some...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now