2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14619 | CRITICAL | 9.8 | 0.4% | Dec 13, 2025 | A vulnerability was found in code-projects Student File Management System 1.0. Affected by this vulnerability is an unkn... |
| CVE-2025-14617 | MEDIUM | 5.3 | 0.1% | Dec 13, 2025 | A vulnerability has been found in Jehovahs Witnesses JW Library App up to 15.5.1 on Android. Affected is an unknown func... |
| CVE-2025-14607 | MEDIUM | 6.3 | 0.2% | Dec 13, 2025 | A vulnerability was detected in OFFIS DCMTK up to 3.6.9. Affected by this issue is the function DcmByteString::makeDicom... |
| CVE-2025-14606 | MEDIUM | 5 | 0.2% | Dec 13, 2025 | A security vulnerability has been detected in tiny-rdm Tiny RDM up to 1.2.5. Affected by this vulnerability is the funct... |
| CVE-2025-14590 | CRITICAL | 9.8 | 0.4% | Dec 13, 2025 | A security vulnerability has been detected in code-projects Prison Management System 2.0. Impacted is an unknown functio... |
| CVE-2025-14589 | HIGH | 8.8 | 0.3% | Dec 13, 2025 | A weakness has been identified in code-projects Prison Management System 2.0. This issue affects some unknown processing... |
| CVE-2025-14588 | CRITICAL | 9.8 | 0.3% | Dec 13, 2025 | A security flaw has been discovered in itsourcecode Student Management System 1.0. This vulnerability affects unknown co... |
| CVE-2025-14587 | CRITICAL | 9.8 | 0.3% | Dec 13, 2025 | A vulnerability was identified in itsourcecode Online Pet Shop Management System 1.0. This affects an unknown part of th... |
| CVE-2025-14586 | CRITICAL | 9.8 | 2.8% | Dec 13, 2025 | A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprint... |
| CVE-2025-14581 | MEDIUM | 4.3 | 0.2% | Dec 13, 2025 | The HAPPY – Helpdesk Support Ticket System plugin for WordPress is vulnerable to authorization bypass due to a missing c... |
| CVE-2025-14542 | HIGH | 7.5 | 0.2% | Dec 13, 2025 | The vulnerability arises when a client fetches a tools’ JSON specification, known as a Manual, from a remote Manual Endp... |
| CVE-2025-14540 | MEDIUM | 4.3 | 0.2% | Dec 13, 2025 | The Userback plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ... |
| CVE-2025-14539 | MEDIUM | 5.4 | 0.2% | Dec 13, 2025 | The The Shortcode Ajax plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and in... |
| CVE-2025-14508 | MEDIUM | 6.5 | 0.2% | Dec 13, 2025 | The MediaCommander – Bring Folders to Media, Posts, and Pages plugin for WordPress is vulnerable to unauthorized data de... |
| CVE-2025-14477 | MEDIUM | 4.9 | 0.3% | Dec 13, 2025 | The 404 Solution plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.1.0 due to ... |
| CVE-2025-14476 | HIGH | 8.8 | 0.5% | Dec 13, 2025 | The Doubly – Cross Domain Copy Paste for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all ver... |
| CVE-2025-14475 | HIGH | 8.1 | 0.6% | Dec 13, 2025 | The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in all vers... |
| CVE-2025-14462 | MEDIUM | 4.3 | 0.1% | Dec 13, 2025 | The Lucky Draw Contests plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2025-14454 | MEDIUM | 4.3 | 0.1% | Dec 13, 2025 | The Image Slider by Ays- Responsive Slider and Carousel plugin for WordPress is vulnerable to Cross-Site Request Forgery... |
| CVE-2025-14451 | MEDIUM | 4.7 | 0.2% | Dec 13, 2025 | The Solutions Ad Manager plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.0.0... |
| CVE-2025-14447 | MEDIUM | 4.3 | 0.2% | Dec 13, 2025 | The AnnunciFunebri Impresa plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa... |
| CVE-2025-14446 | MEDIUM | 5.4 | 0.2% | Dec 13, 2025 | The Popup Builder (Easy Notify Lite) plugin for WordPress is vulnerable to unauthorized modification of data due to a mi... |
| CVE-2025-14440 | CRITICAL | 9.8 | 0.7% | Dec 13, 2025 | The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2... |
| CVE-2025-14397 | HIGH | 8.8 | 0.2% | Dec 13, 2025 | The Postem Ipsum plugin for WordPress is vulnerable to unauthorized modification of data to Privilege Escalation due to ... |
| CVE-2025-14395 | MEDIUM | 4.3 | 0.2% | Dec 13, 2025 | The Popover Windows plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now