2025 CVE Vulnerabilities

45,168 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14597Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-12700Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-34290HIGH8.5Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerabili...
CVE-2025-7782HIGH7.6The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to unauthorized modification of data due...
CVE-2025-7733MEDIUM4.3The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Insecure Direct Object Reference in a...
CVE-2025-14298MEDIUM5.4The FiboSearch – Ajax Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p...
CVE-2025-12492MEDIUM5.3The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2025-13619CRITICAL9.8The Flex Store Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1....
CVE-2025-12820MEDIUM5.3The Pure WC Variation Swatches WordPress plugin through 1.1.7 does not have an authorization check when updating its set...
CVE-2025-14735MEDIUM4.4The "Amazon affiliate lite Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings ...
CVE-2025-14734MEDIUM5.4The Amazon affiliate lite Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-14721MEDIUM5.5The Responsive and Swipe slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rsSli...
CVE-2025-14633MEDIUM5.3The F70 Lead Document Download plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi...
CVE-2025-14591HIGH7.5In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windo...
CVE-2025-14168MEDIUM4.3The WP DB Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-14164MEDIUM4.3The Quran Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-13624MEDIUM6.1The Overstock Affiliate Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PH...
CVE-2025-13365MEDIUM6.1The WP Hallo Welt plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-13329CRITICAL9.8The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type ...
CVE-2025-12898MEDIUM5.3The Pretty Google Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability...
CVE-2025-12581MEDIUM6.1The Attachments Handler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up ...
CVE-2025-8065MEDIUM6.5A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6....
CVE-2025-14300HIGH8.1The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5  exposes a connectAP interface without proper authenticatio...
CVE-2025-14299MEDIUM6.5The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer over...
CVE-2025-68613HIGH8.8n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now