2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-41768MEDIUM5.5An high privileged remote attacker can inject arbitrary content into the custom CSS field on the affected devices due to...
CVE-2025-66523MEDIUM6.1URL parameters are directly embedded into JavaScript code or HTML attributes without proper encoding or sanitization. Th...
CVE-2025-12573MEDIUM6.5The Bookingor WordPress plugin through 1.0.12 exposes authenticated AJAX actions without capability or nonce checks, al...
CVE-2025-14348MEDIUM5.3The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for Wo...
CVE-2025-14798MEDIUM5.3The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, a...
CVE-2025-14351MEDIUM5.3The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to unauthorized loss of data due to a miss...
CVE-2025-14978MEDIUM5.3The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) plugin for W...
CVE-2025-15466MEDIUM5.4The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to unauthorized access and modification of d...
CVE-2025-69199MEDIUM6.5Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1....
CVE-2025-69198MEDIUM6.5Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to ...
CVE-2025-55250MEDIUM5.3HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical detail...
CVE-2025-55249MEDIUM5.3HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may ...
CVE-2025-52661MEDIUM5.3HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse,...
CVE-2025-59355MEDIUM6.5A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records t...
CVE-2025-15537MEDIUM5.5A security vulnerability has been detected in Mapnik up to 4.2.0. This issue affects the function mapnik::dbf_file::stri...
CVE-2025-15536MEDIUM5.5A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function opencc::MaxMatchSeg...
CVE-2025-15531MEDIUM5.5A vulnerability was identified in Open5GS up to 2.7.5. This vulnerability affects the function sgwc_bearer_add of the fi...
CVE-2025-8615MEDIUM6.4The CubeWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cubewp_shortcode_taxonomy ...
CVE-2025-14078MEDIUM5.3The PAYGENT for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and inclu...
CVE-2025-12129MEDIUM5.3The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all vers...
CVE-2025-12984MEDIUM4.9The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in...
CVE-2025-14029MEDIUM5.3The Community Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2025-12825MEDIUM5.3The User Registration Using Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a mi...
CVE-2025-12168MEDIUM4.3The Phrase TMS Integration for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to ...
CVE-2025-14463MEDIUM5.3The Payment Button for PayPal plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now