2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-58999MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donation...
CVE-2025-54045MEDIUM4.3Missing Authorization vulnerability in CreativeMindsSolutions CM On Demand Search And Replace cm-on-demand-search-and-re...
CVE-2025-54005MEDIUM4.3Missing Authorization vulnerability in sonalsinha21 SKT Page Builder skt-builder allows Exploiting Incorrectly Configure...
CVE-2025-54004LOW2.7Missing Authorization vulnerability in WC Lovers WCFM – Frontend Manager for WooCommerce wc-frontend-manager allows Expl...
CVE-2025-49300LOW2.7Insertion of Sensitive Information Into Sent Data vulnerability in shinetheme Traveler Option Tree custom-option-tree al...
CVE-2025-13231MEDIUM6.5The Fancy Product Designer plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and ...
CVE-2025-13439MEDIUM5.9The Fancy Product Designer plugin for WordPress is vulnerable to Information Disclosure and PHAR Deserialization in all ...
CVE-2025-11991MEDIUM5.3The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2025-66635HIGH8.6Stack-based buffer overflow vulnerability exists in SEIKO EPSON Web Config. Specially crafted data input by a logged-in ...
CVE-2025-62330MEDIUM5.9HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains acce...
CVE-2025-14252HIGH8.5An Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary me...
CVE-2025-13794MEDIUM4.3The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized modification of data du...
CVE-2025-12809MEDIUM5.3The Dokan Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the...
CVE-2025-66357MEDIUM6.9CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper check for unusual or exceptional conditions. When the...
CVE-2025-61976HIGH8.7CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper check for unusual or exceptional conditions. If a rem...
CVE-2025-59479MEDIUM6.1CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper restriction of rendered UI layers or frames. If a use...
CVE-2025-14777MEDIUM6A flaw was found in Keycloak. An IDOR (Broken Access Control) vulnerability exists in the admin API endpoints for author...
CVE-2025-13956MEDIUM5.3The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing...
CVE-2025-62849CRITICAL9.8An SQL injection vulnerability has been reported to affect several QNAP operating system versions. The remote attackers ...
CVE-2025-62848HIGH7.5A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote ...
CVE-2025-62847HIGH7.5An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP op...
CVE-2025-59385CRITICAL9.8An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. T...
CVE-2025-14749HIGH8.8A vulnerability was identified in Ningyuanda TC155 57.0.2.0. This impacts an unknown function of the file /onvif/device_...
CVE-2025-14748MEDIUM5.4A vulnerability was determined in Ningyuanda TC155 57.0.2.0. This affects an unknown function of the file /onvif/device_...
CVE-2025-14747MEDIUM6.5A vulnerability was found in Ningyuanda TC155 57.0.2.0. The impacted element is an unknown function of the component RTS...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now