2025 CVE Vulnerabilities

45,181 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13006MEDIUM5.3The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in a...
CVE-2025-12417MEDIUM6.4The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-66544Rejected reason: Not used
CVE-2025-66543Rejected reason: Not used
CVE-2025-66542Rejected reason: Not used
CVE-2025-66541Rejected reason: Not used
CVE-2025-66540Rejected reason: Not used
CVE-2025-66539Rejected reason: Not used
CVE-2025-66538Rejected reason: Not used
CVE-2025-66537Rejected reason: Not used
CVE-2025-66536Rejected reason: Not used
CVE-2025-27389MEDIUM5.1A flaw exists in the verification of application installation sources within ColorOS. Under specific conditions, this is...
CVE-2025-13066HIGH8.8The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including,...
CVE-2025-12804MEDIUM6.4The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bookingcalendar' ...
CVE-2025-11759MEDIUM4.3The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Cross-Site Request Forgery...
CVE-2025-62223MEDIUM4.3User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker ...
CVE-2025-14052MEDIUM6.5A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function get...
CVE-2025-66564HIGH7.5Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest...
CVE-2025-66563MEDIUM6.1Monkeytype is a minimalistic and customizable typing test. In 25.49.0 and earlier, there is improper handling of user in...
CVE-2025-66561MEDIUM5.4SysReptor is a fully customizable pentest reporting platform. Prior to 2025.102, there is a Stored Cross-Site Scripting ...
CVE-2025-66559HIGH8Taiko Alethia is an Ethereum-equivalent, permissionless, based rollup designed to scale Ethereum without compromising it...
CVE-2025-14051HIGH8.8A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddres...
CVE-2025-13373HIGH8.7Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could al...
CVE-2025-6946MEDIUM4.8A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances vi...
CVE-2025-66509CRITICAL9.8LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow tr...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now