2025 CVE Vulnerabilities
45,168 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14744 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, poten... |
| CVE-2025-65000 | MEDIUM | 5.3 | 0.2% | Dec 18, 2025 | SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2... |
| CVE-2025-40898 | HIGH | 8.1 | 0.3% | Dec 18, 2025 | A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validatio... |
| CVE-2025-40893 | MEDIUM | 6.1 | 0.2% | Dec 18, 2025 | A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of netwo... |
| CVE-2025-40892 | HIGH | 8.9 | 0.2% | Dec 18, 2025 | A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an... |
| CVE-2025-40891 | MEDIUM | 4.7 | 0.1% | Dec 18, 2025 | A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper val... |
| CVE-2025-14618 | MEDIUM | 4.3 | 0.2% | Dec 18, 2025 | The Sweet Energy Efficiency plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data du... |
| CVE-2025-14437 | HIGH | 7.5 | 2.0% | Dec 18, 2025 | The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ... |
| CVE-2025-14277 | MEDIUM | 4.3 | 0.3% | Dec 18, 2025 | The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all version... |
| CVE-2025-13110 | MEDIUM | 4.3 | 0.3% | Dec 18, 2025 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Re... |
| CVE-2025-10910 | CRITICAL | 9.3 | 0.4% | Dec 18, 2025 | A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online... |
| CVE-2025-40602 | MEDIUM | 6.6 | 1.9% | Dec 18, 2025 | A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance manageme... |
| CVE-2025-64997 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Insufficient permission validation in Checkmk versions prior to 2.4.0p17 and 2.3.0p42 allow low-privileged users to view... |
| CVE-2025-14364 | HIGH | 8.8 | 0.3% | Dec 18, 2025 | The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized modification of data, loss of data, and privil... |
| CVE-2025-13730 | MEDIUM | 6.4 | 0.2% | Dec 18, 2025 | The OpenID Connect Generic Client plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'op... |
| CVE-2025-13641 | HIGH | 8.8 | 0.7% | Dec 18, 2025 | The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclu... |
| CVE-2025-14874 | HIGH | 7.5 | 0.4% | Dec 18, 2025 | A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header t... |
| CVE-2025-6326 | HIGH | 8.1 | 0.3% | Dec 18, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-6324 | HIGH | 7.1 | 0.1% | Dec 18, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MatrixAddons Easy ... |
| CVE-2025-67546 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs WP ERP erp allows Ret... |
| CVE-2025-66119 | HIGH | 7.1 | 0.1% | Dec 18, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel hostel ... |
| CVE-2025-66118 | HIGH | 7.1 | 0.1% | Dec 18, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Sprout Cl... |
| CVE-2025-66117 | HIGH | 7.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in Ays Pro Easy Form easy-form allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2025-66116 | HIGH | 7.5 | 0.2% | Dec 18, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in UserElements Ultimate Member Widgets for Elementor ul... |
| CVE-2025-66104 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in Anton Vanyukov Offload, AI & Optimize with Cloudflare Images cf-images allows Exp... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now