2025 CVE Vulnerabilities
45,168 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62901 | MEDIUM | 6.5 | 0.1% | Dec 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tormorten WP Micro... |
| CVE-2025-62955 | MEDIUM | 4.3 | 0.2% | Dec 21, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HappyDevs TempTool [Show Cu... |
| CVE-2025-14995 | HIGH | 8.8 | 0.6% | Dec 21, 2025 | A vulnerability has been found in Tenda FH1201 1.2.0.14(408). Affected is the function sprintf of the file /goform/SetIp... |
| CVE-2025-14994 | HIGH | 8.8 | 0.6% | Dec 21, 2025 | A flaw has been found in Tenda FH1201 and FH1206 1.2.0.14(408)/1.2.0.8(8155). This impacts the function strcat of the fi... |
| CVE-2025-14855 | HIGH | 7.2 | 0.3% | Dec 21, 2025 | The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all ver... |
| CVE-2025-14800 | HIGH | 8.1 | 0.3% | Dec 21, 2025 | The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type... |
| CVE-2025-14993 | HIGH | 8.8 | 0.7% | Dec 21, 2025 | A vulnerability was detected in Tenda AC18 15.03.05.05. This affects the function sprintf of the file /goform/SetDlnaCfg... |
| CVE-2025-9343 | HIGH | 7.2 | 0.2% | Dec 21, 2025 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2025-68644 | HIGH | 7.4 | 0.3% | Dec 21, 2025 | Yealink RPS before 2025-06-27 allows unauthorized access to information, including AutoP URL addresses. This was fixed b... |
| CVE-2025-14992 | HIGH | 8.8 | 0.6% | Dec 21, 2025 | A security vulnerability has been detected in Tenda AC18 15.03.05.05. The impacted element is the function strcpy of the... |
| CVE-2025-14991 | MEDIUM | 4.8 | 0.2% | Dec 21, 2025 | A weakness has been identified in Campcodes Complete Online Beauty Parlor Management System 1.0. The affected element is... |
| CVE-2025-14990 | CRITICAL | 9.8 | 0.3% | Dec 21, 2025 | A security flaw has been discovered in Campcodes Complete Online Beauty Parlor Management System 1.0. Impacted is an unk... |
| CVE-2025-13693 | MEDIUM | 6.4 | 0.2% | Dec 21, 2025 | The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Cust... |
| CVE-2025-13361 | MEDIUM | 4.3 | 0.1% | Dec 21, 2025 | The Web to SugarCRM Lead plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2025-13220 | MEDIUM | 6.4 | 0.2% | Dec 21, 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi... |
| CVE-2025-12654 | LOW | 2.7 | 0.4% | Dec 21, 2025 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory cr... |
| CVE-2025-12398 | MEDIUM | 6.1 | 0.2% | Dec 21, 2025 | The Product Table for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_k... |
| CVE-2025-14080 | MEDIUM | 5.3 | 0.2% | Dec 21, 2025 | The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Missing Authorization in all versions up... |
| CVE-2025-14071 | HIGH | 7.5 | 0.6% | Dec 21, 2025 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all ver... |
| CVE-2025-14054 | MEDIUM | 4.4 | 0.2% | Dec 21, 2025 | The WC Builder – WooCommerce Page Builder for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2025-14043 | MEDIUM | 5.3 | 0.3% | Dec 21, 2025 | The Tainacan plugin for WordPress is vulnerable to unauthorized metadata section creation due to missing authorization c... |
| CVE-2025-13838 | MEDIUM | 6.4 | 0.2% | Dec 21, 2025 | The WishSuite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter of the '... |
| CVE-2025-12980 | HIGH | 7.5 | 0.3% | Dec 21, 2025 | The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthor... |
| CVE-2025-11496 | MEDIUM | 6.1 | 0.2% | Dec 21, 2025 | The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2025-14989 | CRITICAL | 9.8 | 0.3% | Dec 21, 2025 | A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This issue affects some... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now