2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58999 | MEDIUM | 4.3 | 0.1% | Dec 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donation... |
| CVE-2025-54045 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in CreativeMindsSolutions CM On Demand Search And Replace cm-on-demand-search-and-re... |
| CVE-2025-54005 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in sonalsinha21 SKT Page Builder skt-builder allows Exploiting Incorrectly Configure... |
| CVE-2025-54004 | LOW | 2.7 | 0.3% | Dec 16, 2025 | Missing Authorization vulnerability in WC Lovers WCFM – Frontend Manager for WooCommerce wc-frontend-manager allows Expl... |
| CVE-2025-49300 | LOW | 2.7 | 0.2% | Dec 16, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in shinetheme Traveler Option Tree custom-option-tree al... |
| CVE-2025-13231 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | The Fancy Product Designer plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and ... |
| CVE-2025-13439 | MEDIUM | 5.9 | 0.3% | Dec 16, 2025 | The Fancy Product Designer plugin for WordPress is vulnerable to Information Disclosure and PHAR Deserialization in all ... |
| CVE-2025-11991 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to unauthorized modification of data... |
| CVE-2025-66635 | HIGH | 8.6 | 0.5% | Dec 16, 2025 | Stack-based buffer overflow vulnerability exists in SEIKO EPSON Web Config. Specially crafted data input by a logged-in ... |
| CVE-2025-62330 | MEDIUM | 5.9 | 0.1% | Dec 16, 2025 | HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains acce... |
| CVE-2025-14252 | HIGH | 8.5 | 0.1% | Dec 16, 2025 | An Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary me... |
| CVE-2025-13794 | MEDIUM | 4.3 | 0.3% | Dec 16, 2025 | The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized modification of data du... |
| CVE-2025-12809 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | The Dokan Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the... |
| CVE-2025-66357 | MEDIUM | 6.9 | 0.3% | Dec 16, 2025 | CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper check for unusual or exceptional conditions. When the... |
| CVE-2025-61976 | HIGH | 8.7 | 0.4% | Dec 16, 2025 | CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper check for unusual or exceptional conditions. If a rem... |
| CVE-2025-59479 | MEDIUM | 6.1 | 0.2% | Dec 16, 2025 | CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper restriction of rendered UI layers or frames. If a use... |
| CVE-2025-14777 | MEDIUM | 6 | 0.3% | Dec 16, 2025 | A flaw was found in Keycloak. An IDOR (Broken Access Control) vulnerability exists in the admin API endpoints for author... |
| CVE-2025-13956 | MEDIUM | 5.3 | 0.9% | Dec 16, 2025 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing... |
| CVE-2025-62849 | CRITICAL | 9.8 | 0.9% | Dec 16, 2025 | An SQL injection vulnerability has been reported to affect several QNAP operating system versions. The remote attackers ... |
| CVE-2025-62848 | HIGH | 7.5 | 0.8% | Dec 16, 2025 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote ... |
| CVE-2025-62847 | HIGH | 7.5 | 0.8% | Dec 16, 2025 | An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP op... |
| CVE-2025-59385 | CRITICAL | 9.8 | 0.6% | Dec 16, 2025 | An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. T... |
| CVE-2025-14749 | HIGH | 8.8 | 0.7% | Dec 16, 2025 | A vulnerability was identified in Ningyuanda TC155 57.0.2.0. This impacts an unknown function of the file /onvif/device_... |
| CVE-2025-14748 | MEDIUM | 5.4 | 0.6% | Dec 16, 2025 | A vulnerability was determined in Ningyuanda TC155 57.0.2.0. This affects an unknown function of the file /onvif/device_... |
| CVE-2025-14747 | MEDIUM | 6.5 | 0.6% | Dec 16, 2025 | A vulnerability was found in Ningyuanda TC155 57.0.2.0. The impacted element is an unknown function of the component RTS... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now