2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-14978MEDIUM5.3The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) plugin for W...
CVE-2025-15466MEDIUM5.4The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to unauthorized access and modification of d...
CVE-2025-69199MEDIUM6.5Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1....
CVE-2025-69198MEDIUM6.5Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to ...
CVE-2025-55250MEDIUM5.3HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical detail...
CVE-2025-55249MEDIUM5.3HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may ...
CVE-2025-52661MEDIUM5.3HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse,...
CVE-2025-59355MEDIUM6.5A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records t...
CVE-2025-15537MEDIUM5.5A security vulnerability has been detected in Mapnik up to 4.2.0. This issue affects the function mapnik::dbf_file::stri...
CVE-2025-15536MEDIUM5.5A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vulnerability affects the function opencc::MaxMatchSeg...
CVE-2025-15531MEDIUM5.5A vulnerability was identified in Open5GS up to 2.7.5. This vulnerability affects the function sgwc_bearer_add of the fi...
CVE-2025-8615MEDIUM6.4The CubeWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cubewp_shortcode_taxonomy ...
CVE-2025-14078MEDIUM5.3The PAYGENT for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and inclu...
CVE-2025-12129MEDIUM5.3The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all vers...
CVE-2025-12984MEDIUM4.9The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in...
CVE-2025-14029MEDIUM5.3The Community Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2025-12825MEDIUM5.3The User Registration Using Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a mi...
CVE-2025-12168MEDIUM4.3The Phrase TMS Integration for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to ...
CVE-2025-14463MEDIUM5.3The Payment Button for PayPal plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, a...
CVE-2025-13725MEDIUM6.5The Gutenberg Thim Blocks – Page Builder, Gutenberg Blocks for the Block Editor plugin for WordPress is vulnerable to ar...
CVE-2025-14632MEDIUM4.4The Filr – Secure document library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via unrestricted fi...
CVE-2025-14450MEDIUM6.5The Wallet System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2025-14075MEDIUM5.3The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc...
CVE-2025-12718MEDIUM5.8The Quick Contact Form plugin for WordPress is vulnerable to Open Mail Relay in all versions up to, and including, 8.2.6...
CVE-2025-12002MEDIUM5.9The Feeds for YouTube Pro plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now