2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13365 | MEDIUM | 6.1 | 0.1% | Dec 20, 2025 | The WP Hallo Welt plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-13329 | CRITICAL | 9.8 | 0.6% | Dec 20, 2025 | The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type ... |
| CVE-2025-12898 | MEDIUM | 5.3 | 0.3% | Dec 20, 2025 | The Pretty Google Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability... |
| CVE-2025-12581 | MEDIUM | 6.1 | 0.2% | Dec 20, 2025 | The Attachments Handler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up ... |
| CVE-2025-8065 | MEDIUM | 6.5 | 0.5% | Dec 20, 2025 | A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6.... |
| CVE-2025-14300 | HIGH | 8.1 | 0.4% | Dec 20, 2025 | The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5 exposes a connectAP interface without proper authenticatio... |
| CVE-2025-14299 | MEDIUM | 6.5 | 0.2% | Dec 20, 2025 | The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer over... |
| CVE-2025-68613 | HIGH | 8.8 | 97.9% | Dec 19, 2025 | n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.... |
| CVE-2025-68481 | HIGH | 8.8 | 0.2% | Dec 19, 2025 | FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to ve... |
| CVE-2025-67712 | MEDIUM | 4.7 | 0.3% | Dec 19, 2025 | There is an HTML injection issue in Esri ArcGIS Web AppBuilder developer edition versions prior to 2.30 that allows a re... |
| CVE-2025-14968 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | A security flaw has been discovered in code-projects Simple Stock System 1.0. Affected by this issue is some unknown fun... |
| CVE-2025-14967 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | A vulnerability was identified in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unkno... |
| CVE-2025-14966 | HIGH | 7.2 | 0.3% | Dec 19, 2025 | A vulnerability was determined in FastAdmin up to 1.7.0.20250506. Affected is the function selectpage of the file applic... |
| CVE-2025-12874 | MEDIUM | 6.3 | 0.4% | Dec 19, 2025 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Quest Coexistence Mana... |
| CVE-2025-14965 | MEDIUM | 5.5 | 0.3% | Dec 19, 2025 | A vulnerability was found in 1541492390c yougou-mall up to 0a771fa817c924efe52c8fe0a9a6658eee675f9f. This impacts the fu... |
| CVE-2025-14964 | CRITICAL | 9.8 | 0.9% | Dec 19, 2025 | A vulnerability has been found in TOTOLINK T10 4.1.8cu.5083_B20200521. This affects the function sprintf of the file /cg... |
| CVE-2025-14962 | MEDIUM | 6.1 | 0.3% | Dec 19, 2025 | A flaw has been found in code-projects Simple Stock System 1.0. The impacted element is an unknown function of the file ... |
| CVE-2025-14961 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | A vulnerability was detected in code-projects Simple Blood Donor Management System 1.0. The affected element is an unkno... |
| CVE-2025-68478 | HIGH | 7.1 | 3.6% | Dec 19, 2025 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary p... |
| CVE-2025-68430 | MEDIUM | 4.3 | 0.2% | Dec 19, 2025 | CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.8.1 through 2.52.0... |
| CVE-2025-14960 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | A security vulnerability has been detected in code-projects Simple Blood Donor Management System 1.0. Impacted is an unk... |
| CVE-2025-14959 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | A weakness has been identified in code-projects Simple Stock System 1.0. This issue affects some unknown processing of t... |
| CVE-2025-14958 | HIGH | 7.8 | 0.2% | Dec 19, 2025 | A security flaw has been discovered in floooh sokol up to 33e2271c431bf21de001e972f72da17a984da932. This vulnerability a... |
| CVE-2025-68477 | MEDIUM | 6.5 | 5.8% | Dec 19, 2025 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, Langflow provides... |
| CVE-2025-68457 | MEDIUM | 6.1 | 0.2% | Dec 19, 2025 | Orejime is a consent manager that focuses on accessibility. On HTML elements handled by Orejime prior to version 2.3.2, ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now