2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13365MEDIUM6.1The WP Hallo Welt plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-13329CRITICAL9.8The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type ...
CVE-2025-12898MEDIUM5.3The Pretty Google Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability...
CVE-2025-12581MEDIUM6.1The Attachments Handler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up ...
CVE-2025-8065MEDIUM6.5A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6....
CVE-2025-14300HIGH8.1The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5  exposes a connectAP interface without proper authenticatio...
CVE-2025-14299MEDIUM6.5The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer over...
CVE-2025-68613HIGH8.8n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1....
CVE-2025-68481HIGH8.8FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to ve...
CVE-2025-67712MEDIUM4.7There is an HTML injection issue in Esri ArcGIS Web AppBuilder developer edition versions prior to 2.30 that allows a re...
CVE-2025-14968CRITICAL9.8A security flaw has been discovered in code-projects Simple Stock System 1.0. Affected by this issue is some unknown fun...
CVE-2025-14967CRITICAL9.8A vulnerability was identified in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unkno...
CVE-2025-14966HIGH7.2A vulnerability was determined in FastAdmin up to 1.7.0.20250506. Affected is the function selectpage of the file applic...
CVE-2025-12874MEDIUM6.3Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Quest Coexistence Mana...
CVE-2025-14965MEDIUM5.5A vulnerability was found in 1541492390c yougou-mall up to 0a771fa817c924efe52c8fe0a9a6658eee675f9f. This impacts the fu...
CVE-2025-14964CRITICAL9.8A vulnerability has been found in TOTOLINK T10 4.1.8cu.5083_B20200521. This affects the function sprintf of the file /cg...
CVE-2025-14962MEDIUM6.1A flaw has been found in code-projects Simple Stock System 1.0. The impacted element is an unknown function of the file ...
CVE-2025-14961CRITICAL9.8A vulnerability was detected in code-projects Simple Blood Donor Management System 1.0. The affected element is an unkno...
CVE-2025-68478HIGH7.1Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary p...
CVE-2025-68430MEDIUM4.3CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.8.1 through 2.52.0...
CVE-2025-14960CRITICAL9.8A security vulnerability has been detected in code-projects Simple Blood Donor Management System 1.0. Impacted is an unk...
CVE-2025-14959CRITICAL9.8A weakness has been identified in code-projects Simple Stock System 1.0. This issue affects some unknown processing of t...
CVE-2025-14958HIGH7.8A security flaw has been discovered in floooh sokol up to 33e2271c431bf21de001e972f72da17a984da932. This vulnerability a...
CVE-2025-68477MEDIUM6.5Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, Langflow provides...
CVE-2025-68457MEDIUM6.1Orejime is a consent manager that focuses on accessibility. On HTML elements handled by Orejime prior to version 2.3.2, ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now