2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41768 | MEDIUM | 5.5 | 0.2% | Jan 20, 2026 | An high privileged remote attacker can inject arbitrary content into the custom CSS field on the affected devices due to... |
| CVE-2025-66523 | MEDIUM | 6.1 | 0.2% | Jan 20, 2026 | URL parameters are directly embedded into JavaScript code or HTML attributes without proper encoding or sanitization. Th... |
| CVE-2025-12573 | MEDIUM | 6.5 | 0.2% | Jan 20, 2026 | The Bookingor WordPress plugin through 1.0.12 exposes authenticated AJAX actions without capability or nonce checks, al... |
| CVE-2025-14348 | MEDIUM | 5.3 | 0.3% | Jan 20, 2026 | The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for Wo... |
| CVE-2025-14798 | MEDIUM | 5.3 | 0.2% | Jan 20, 2026 | The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, a... |
| CVE-2025-14351 | MEDIUM | 5.3 | 0.2% | Jan 20, 2026 | The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to unauthorized loss of data due to a miss... |
| CVE-2025-14978 | MEDIUM | 5.3 | 0.2% | Jan 20, 2026 | The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) plugin for W... |
| CVE-2025-15466 | MEDIUM | 5.4 | 0.2% | Jan 20, 2026 | The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to unauthorized access and modification of d... |
| CVE-2025-69199 | MEDIUM | 6.5 | 0.3% | Jan 19, 2026 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.... |
| CVE-2025-69198 | MEDIUM | 6.5 | 0.2% | Jan 19, 2026 | Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to ... |
| CVE-2025-55250 | MEDIUM | 5.3 | 0.1% | Jan 19, 2026 | HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical detail... |
| CVE-2025-55249 | MEDIUM | 5.3 | 0.2% | Jan 19, 2026 | HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may ... |
| CVE-2025-52661 | MEDIUM | 5.3 | 0.1% | Jan 19, 2026 | HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse,... |
| CVE-2025-59355 | MEDIUM | 6.5 | 0.4% | Jan 19, 2026 | A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records t... |
| CVE-2025-15537 | MEDIUM | 5.5 | 0.2% | Jan 18, 2026 | A security vulnerability has been detected in Mapnik up to 4.2.0. This issue affects the function mapnik::dbf_file::stri... |
| CVE-2025-15536 | MEDIUM | 5.5 | 0.2% | Jan 18, 2026 | A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function opencc::MaxMatchSeg... |
| CVE-2025-15531 | MEDIUM | 5.5 | 0.7% | Jan 17, 2026 | A vulnerability was identified in Open5GS up to 2.7.5. This vulnerability affects the function sgwc_bearer_add of the fi... |
| CVE-2025-8615 | MEDIUM | 6.4 | 0.2% | Jan 17, 2026 | The CubeWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cubewp_shortcode_taxonomy ... |
| CVE-2025-14078 | MEDIUM | 5.3 | 0.3% | Jan 17, 2026 | The PAYGENT for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and inclu... |
| CVE-2025-12129 | MEDIUM | 5.3 | 0.2% | Jan 17, 2026 | The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all vers... |
| CVE-2025-12984 | MEDIUM | 4.9 | 0.3% | Jan 17, 2026 | The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in... |
| CVE-2025-14029 | MEDIUM | 5.3 | 0.2% | Jan 17, 2026 | The Community Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2025-12825 | MEDIUM | 5.3 | 0.5% | Jan 17, 2026 | The User Registration Using Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a mi... |
| CVE-2025-12168 | MEDIUM | 4.3 | 0.2% | Jan 17, 2026 | The Phrase TMS Integration for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to ... |
| CVE-2025-14463 | MEDIUM | 5.3 | 0.3% | Jan 17, 2026 | The Payment Button for PayPal plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now