2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13506 | HIGH | 8.8 | 0.4% | Dec 12, 2025 | Execution with Unnecessary Privileges vulnerability in Nebim Neyir Computer Industry and Services Inc. Nebim V3 ERP allo... |
| CVE-2025-14442 | MEDIUM | 5.3 | 0.3% | Dec 12, 2025 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to sensitive information expos... |
| CVE-2025-14159 | MEDIUM | 4.3 | 0.1% | Dec 12, 2025 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Cross-Site Request Forgery ... |
| CVE-2025-14065 | MEDIUM | 4.3 | 0.2% | Dec 12, 2025 | The Simple Bike Rental plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability che... |
| CVE-2025-14030 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The AI Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aife_post_meta' shortcode in all... |
| CVE-2025-12965 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Magical Posts Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mpac_title_tag' par... |
| CVE-2025-12408 | MEDIUM | 5.3 | 0.3% | Dec 12, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure i... |
| CVE-2025-12407 | MEDIUM | 4.3 | 0.1% | Dec 12, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request For... |
| CVE-2025-12841 | MEDIUM | 5.3 | 0.7% | Dec 12, 2025 | The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of t... |
| CVE-2025-12835 | HIGH | 7.3 | 0.2% | Dec 12, 2025 | The WooMulti WordPress plugin through 17 does not validate a file parameter when deleting files, which could allow any a... |
| CVE-2025-58137 | HIGH | 8.1 | 0.3% | Dec 12, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: ... |
| CVE-2025-58130 | CRITICAL | 9.1 | 0.4% | Dec 12, 2025 | Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11... |
| CVE-2025-26866 | HIGH | 8.8 | 0.8% | Dec 12, 2025 | A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization wi... |
| CVE-2025-23408 | MEDIUM | 6.5 | 0.4% | Dec 12, 2025 | Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.10.1. The is... |
| CVE-2025-14074 | MEDIUM | 4.3 | 0.2% | Dec 12, 2025 | The PDF for Contact Form 7 + Drag and Drop Template Builder plugin for WordPress is vulnerable to unauthorized post dupl... |
| CVE-2025-13993 | MEDIUM | 5.5 | 0.3% | Dec 12, 2025 | The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form... |
| CVE-2025-12348 | MEDIUM | 5.3 | 0.4% | Dec 12, 2025 | The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Miss... |
| CVE-2025-40829 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applications contains an uni... |
| CVE-2025-12960 | MEDIUM | 6.5 | 0.6% | Dec 12, 2025 | The Simple CSV Table plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0... |
| CVE-2025-67731 | HIGH | 7.5 | 0.3% | Dec 12, 2025 | Servify Express is a Node.js package to start an Express server and log the port it's running on. Prior to 1.2, the Expr... |
| CVE-2025-67730 | MEDIUM | 5.4 | 0.1% | Dec 12, 2025 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to... |
| CVE-2025-4970 | MEDIUM | 5.5 | 0.3% | Dec 12, 2025 | The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio... |
| CVE-2025-14169 | HIGH | 7.5 | 0.3% | Dec 12, 2025 | The FunnelKit - Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to time-based blind SQL Injec... |
| CVE-2025-14049 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | The VikRentItems Flexible Rental Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ... |
| CVE-2025-13891 | MEDIUM | 6.5 | 0.4% | Dec 12, 2025 | The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now