2025 CVE Vulnerabilities
45,168 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14597 | — | — | — | Dec 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-12700 | — | — | — | Dec 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-34290 | HIGH | 8.5 | 0.1% | Dec 20, 2025 | Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerabili... |
| CVE-2025-7782 | HIGH | 7.6 | 0.2% | Dec 20, 2025 | The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to unauthorized modification of data due... |
| CVE-2025-7733 | MEDIUM | 4.3 | 0.2% | Dec 20, 2025 | The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Insecure Direct Object Reference in a... |
| CVE-2025-14298 | MEDIUM | 5.4 | 0.3% | Dec 20, 2025 | The FiboSearch – Ajax Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p... |
| CVE-2025-12492 | MEDIUM | 5.3 | 0.4% | Dec 20, 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi... |
| CVE-2025-13619 | CRITICAL | 9.8 | 0.3% | Dec 20, 2025 | The Flex Store Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.... |
| CVE-2025-12820 | MEDIUM | 5.3 | 0.2% | Dec 20, 2025 | The Pure WC Variation Swatches WordPress plugin through 1.1.7 does not have an authorization check when updating its set... |
| CVE-2025-14735 | MEDIUM | 4.4 | 0.2% | Dec 20, 2025 | The "Amazon affiliate lite Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings ... |
| CVE-2025-14734 | MEDIUM | 5.4 | 0.1% | Dec 20, 2025 | The Amazon affiliate lite Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2025-14721 | MEDIUM | 5.5 | 0.2% | Dec 20, 2025 | The Responsive and Swipe slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rsSli... |
| CVE-2025-14633 | MEDIUM | 5.3 | 0.2% | Dec 20, 2025 | The F70 Lead Document Download plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi... |
| CVE-2025-14591 | HIGH | 7.5 | 0.2% | Dec 20, 2025 | In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windo... |
| CVE-2025-14168 | MEDIUM | 4.3 | 0.1% | Dec 20, 2025 | The WP DB Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-14164 | MEDIUM | 4.3 | 0.1% | Dec 20, 2025 | The Quran Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-13624 | MEDIUM | 6.1 | 0.2% | Dec 20, 2025 | The Overstock Affiliate Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PH... |
| CVE-2025-13365 | MEDIUM | 6.1 | 0.1% | Dec 20, 2025 | The WP Hallo Welt plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-13329 | CRITICAL | 9.8 | 0.6% | Dec 20, 2025 | The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type ... |
| CVE-2025-12898 | MEDIUM | 5.3 | 0.2% | Dec 20, 2025 | The Pretty Google Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability... |
| CVE-2025-12581 | MEDIUM | 6.1 | 0.2% | Dec 20, 2025 | The Attachments Handler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up ... |
| CVE-2025-8065 | MEDIUM | 6.5 | 0.5% | Dec 20, 2025 | A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6.... |
| CVE-2025-14300 | HIGH | 8.1 | 0.3% | Dec 20, 2025 | The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5 exposes a connectAP interface without proper authenticatio... |
| CVE-2025-14299 | MEDIUM | 6.5 | 0.2% | Dec 20, 2025 | The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer over... |
| CVE-2025-68613 | HIGH | 8.8 | 97.9% | Dec 19, 2025 | n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now