2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13506HIGH8.8Execution with Unnecessary Privileges vulnerability in Nebim Neyir Computer Industry and Services Inc. Nebim V3 ERP allo...
CVE-2025-14442MEDIUM5.3The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to sensitive information expos...
CVE-2025-14159MEDIUM4.3The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Cross-Site Request Forgery ...
CVE-2025-14065MEDIUM4.3The Simple Bike Rental plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability che...
CVE-2025-14030MEDIUM6.4The AI Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aife_post_meta' shortcode in all...
CVE-2025-12965MEDIUM6.4The Magical Posts Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mpac_title_tag' par...
CVE-2025-12408MEDIUM5.3The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure i...
CVE-2025-12407MEDIUM4.3The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request For...
CVE-2025-12841MEDIUM5.3The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of t...
CVE-2025-12835HIGH7.3The WooMulti WordPress plugin through 17 does not validate a file parameter when deleting files, which could allow any a...
CVE-2025-58137HIGH8.1Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: ...
CVE-2025-58130CRITICAL9.1Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11...
CVE-2025-26866HIGH8.8A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization wi...
CVE-2025-23408MEDIUM6.5Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.10.1. The is...
CVE-2025-14074MEDIUM4.3The PDF for Contact Form 7 + Drag and Drop Template Builder plugin for WordPress is vulnerable to unauthorized post dupl...
CVE-2025-13993MEDIUM5.5The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form...
CVE-2025-12348MEDIUM5.3The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Miss...
CVE-2025-40829HIGH7.8A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applications contains an uni...
CVE-2025-12960MEDIUM6.5The Simple CSV Table plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0...
CVE-2025-67731HIGH7.5Servify Express is a Node.js package to start an Express server and log the port it's running on. Prior to 1.2, the Expr...
CVE-2025-67730MEDIUM5.4Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to...
CVE-2025-4970MEDIUM5.5The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio...
CVE-2025-14169HIGH7.5The FunnelKit - Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to time-based blind SQL Injec...
CVE-2025-14049MEDIUM6.1The VikRentItems Flexible Rental Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ...
CVE-2025-13891MEDIUM6.5The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now