2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12835 | HIGH | 7.3 | 0.2% | Dec 12, 2025 | The WooMulti WordPress plugin through 17 does not validate a file parameter when deleting files, which could allow any a... |
| CVE-2025-58137 | HIGH | 8.1 | 0.3% | Dec 12, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: ... |
| CVE-2025-58130 | CRITICAL | 9.1 | 0.4% | Dec 12, 2025 | Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11... |
| CVE-2025-26866 | HIGH | 8.8 | 0.8% | Dec 12, 2025 | A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization wi... |
| CVE-2025-23408 | MEDIUM | 6.5 | 0.4% | Dec 12, 2025 | Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.10.1. The is... |
| CVE-2025-14074 | MEDIUM | 4.3 | 0.2% | Dec 12, 2025 | The PDF for Contact Form 7 + Drag and Drop Template Builder plugin for WordPress is vulnerable to unauthorized post dupl... |
| CVE-2025-13993 | MEDIUM | 5.5 | 0.3% | Dec 12, 2025 | The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form... |
| CVE-2025-12348 | MEDIUM | 5.3 | 0.4% | Dec 12, 2025 | The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Miss... |
| CVE-2025-40829 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applications contains an uni... |
| CVE-2025-12960 | MEDIUM | 6.5 | 0.6% | Dec 12, 2025 | The Simple CSV Table plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0... |
| CVE-2025-67731 | HIGH | 7.5 | 0.3% | Dec 12, 2025 | Servify Express is a Node.js package to start an Express server and log the port it's running on. Prior to 1.2, the Expr... |
| CVE-2025-67730 | MEDIUM | 5.4 | 0.1% | Dec 12, 2025 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to... |
| CVE-2025-4970 | MEDIUM | 5.5 | 0.3% | Dec 12, 2025 | The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio... |
| CVE-2025-14169 | HIGH | 7.5 | 0.3% | Dec 12, 2025 | The FunnelKit - Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to time-based blind SQL Injec... |
| CVE-2025-14049 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | The VikRentItems Flexible Rental Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ... |
| CVE-2025-13891 | MEDIUM | 6.5 | 0.4% | Dec 12, 2025 | The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up t... |
| CVE-2025-11876 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Mailgun Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mailgun_su... |
| CVE-2025-10583 | LOW | 3.5 | 0.2% | Dec 12, 2025 | The WP Fastest Cache Premium plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an... |
| CVE-2025-67737 | LOW | 3.7 | 0.2% | Dec 12, 2025 | AzuraCast is a self-hosted, all-in-one web radio management suite. Versions 0.23.1 mistakenly include an API endpoint th... |
| CVE-2025-67728 | CRITICAL | 9.8 | 0.6% | Dec 12, 2025 | Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unau... |
| CVE-2025-67727 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior t... |
| CVE-2025-67726 | HIGH | 7.5 | 0.4% | Dec 12, 2025 | Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algor... |
| CVE-2025-14356 | MEDIUM | 4.3 | 0.3% | Dec 12, 2025 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing c... |
| CVE-2025-14068 | HIGH | 7.5 | 0.3% | Dec 12, 2025 | The WPNakama plugin for WordPress is vulnerable to time-based SQL Injection via the 'order_by' parameter in all versions... |
| CVE-2025-13660 | MEDIUM | 5.3 | 0.3% | Dec 12, 2025 | The Guest Support plugin for WordPress is vulnerable to User Email Disclosure in versions up to, and including, 1.2.3. T... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now