2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12835HIGH7.3The WooMulti WordPress plugin through 17 does not validate a file parameter when deleting files, which could allow any a...
CVE-2025-58137HIGH8.1Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: ...
CVE-2025-58130CRITICAL9.1Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11...
CVE-2025-26866HIGH8.8A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization wi...
CVE-2025-23408MEDIUM6.5Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.10.1. The is...
CVE-2025-14074MEDIUM4.3The PDF for Contact Form 7 + Drag and Drop Template Builder plugin for WordPress is vulnerable to unauthorized post dupl...
CVE-2025-13993MEDIUM5.5The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form...
CVE-2025-12348MEDIUM5.3The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Miss...
CVE-2025-40829HIGH7.8A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applications contains an uni...
CVE-2025-12960MEDIUM6.5The Simple CSV Table plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0...
CVE-2025-67731HIGH7.5Servify Express is a Node.js package to start an Express server and log the port it's running on. Prior to 1.2, the Expr...
CVE-2025-67730MEDIUM5.4Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to...
CVE-2025-4970MEDIUM5.5The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio...
CVE-2025-14169HIGH7.5The FunnelKit - Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to time-based blind SQL Injec...
CVE-2025-14049MEDIUM6.1The VikRentItems Flexible Rental Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ...
CVE-2025-13891MEDIUM6.5The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up t...
CVE-2025-11876MEDIUM6.4The Mailgun Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mailgun_su...
CVE-2025-10583LOW3.5The WP Fastest Cache Premium plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an...
CVE-2025-67737LOW3.7AzuraCast is a self-hosted, all-in-one web radio management suite. Versions 0.23.1 mistakenly include an API endpoint th...
CVE-2025-67728CRITICAL9.8Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unau...
CVE-2025-67727CRITICAL9.8Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior t...
CVE-2025-67726HIGH7.5Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algor...
CVE-2025-14356MEDIUM4.3The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing c...
CVE-2025-14068HIGH7.5The WPNakama plugin for WordPress is vulnerable to time-based SQL Injection via the 'order_by' parameter in all versions...
CVE-2025-13660MEDIUM5.3The Guest Support plugin for WordPress is vulnerable to User Email Disclosure in versions up to, and including, 1.2.3. T...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now