2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14645 | CRITICAL | 9.8 | 0.4% | Dec 14, 2025 | A vulnerability was identified in code-projects Student File Management System 1.0. This affects an unknown function of ... |
| CVE-2025-12696 | MEDIUM | 5.3 | 0.1% | Dec 14, 2025 | The HelloLeads CRM Form Shortcode WordPress plugin through 1.0 does not have authorisation and CSRF check when resetting... |
| CVE-2025-12537 | MEDIUM | 6.4 | 0.2% | Dec 14, 2025 | The Addon Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to... |
| CVE-2025-67897 | MEDIUM | 5.3 | 0.3% | Dec 14, 2025 | In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take adva... |
| CVE-2025-13126 | HIGH | 7.5 | 0.3% | Dec 14, 2025 | The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parame... |
| CVE-2025-67896 | CRITICAL | 9.8 | 0.4% | Dec 14, 2025 | Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow becau... |
| CVE-2025-14644 | CRITICAL | 9.8 | 0.3% | Dec 14, 2025 | A vulnerability was determined in itsourcecode Student Management System 1.0. The impacted element is an unknown functio... |
| CVE-2025-14643 | CRITICAL | 9.8 | 0.4% | Dec 14, 2025 | A vulnerability was found in code-projects Simple Attendance Record System 2.0. The affected element is an unknown funct... |
| CVE-2025-14642 | HIGH | 7.2 | 0.3% | Dec 14, 2025 | A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the f... |
| CVE-2025-14641 | HIGH | 7.2 | 0.3% | Dec 14, 2025 | A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the... |
| CVE-2025-14640 | CRITICAL | 9.8 | 0.4% | Dec 14, 2025 | A flaw has been found in code-projects Student File Management System 1.0. The affected element is an unknown function o... |
| CVE-2025-14639 | CRITICAL | 9.8 | 0.3% | Dec 14, 2025 | A vulnerability was detected in itsourcecode Student Management System 1.0. Impacted is an unknown function of the file ... |
| CVE-2025-14638 | CRITICAL | 9.8 | 0.3% | Dec 14, 2025 | A security vulnerability has been detected in itsourcecode Online Pet Shop Management System 1.0. This issue affects som... |
| CVE-2025-13832 | — | — | — | Dec 13, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-14637 | CRITICAL | 9.8 | 0.3% | Dec 13, 2025 | A weakness has been identified in itsourcecode Online Pet Shop Management System 1.0. This vulnerability affects unknown... |
| CVE-2025-14636 | LOW | 3.7 | 0.2% | Dec 13, 2025 | A security flaw has been discovered in Tenda AX9 22.03.01.46. This affects the function image_check of the component htt... |
| CVE-2025-14623 | CRITICAL | 9.8 | 0.4% | Dec 13, 2025 | A weakness has been identified in code-projects Student File Management System 1.0. This issue affects some unknown proc... |
| CVE-2025-14622 | CRITICAL | 9.8 | 0.4% | Dec 13, 2025 | A security flaw has been discovered in code-projects Student File Management System 1.0. This vulnerability affects unkn... |
| CVE-2025-14621 | CRITICAL | 9.8 | 0.3% | Dec 13, 2025 | A vulnerability was identified in code-projects Student File Management System 1.0. This affects an unknown part of the ... |
| CVE-2025-9873 | MEDIUM | 6.4 | 0.3% | Dec 13, 2025 | The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,... |
| CVE-2025-9856 | MEDIUM | 6.4 | 0.3% | Dec 13, 2025 | The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to St... |
| CVE-2025-9488 | MEDIUM | 6.4 | 0.3% | Dec 13, 2025 | The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data’ parameter in all ve... |
| CVE-2025-9218 | LOW | 3.7 | 0.2% | Dec 13, 2025 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to... |
| CVE-2025-9207 | MEDIUM | 5.3 | 0.4% | Dec 13, 2025 | The TI WooCommerce Wishlist plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2... |
| CVE-2025-9116 | MEDIUM | 5.8 | 0.1% | Dec 13, 2025 | The WPS Visitor Counter WordPress plugin through 1.4.8 does not escape the $_SERVER['REQUEST_URI'] parameter before outp... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now