2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-67859MEDIUM5.1A Improper Authentication vulnerability in TLP allows local users to arbitrarily control the power profile in use as wel...
CVE-2025-66169MEDIUM5.3Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 befo...
CVE-2025-68492MEDIUM4.2Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vuln...
CVE-2025-15513MEDIUM5.3The Float Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to improper error ...
CVE-2025-15512MEDIUM5.3The Aplazo Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa...
CVE-2025-15475MEDIUM5.3The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of da...
CVE-2025-15376MEDIUM4.3The Stopwords for comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2025-14846MEDIUM4.3The SocialChamp with WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2025-14173MEDIUM5.3The Perfit WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,...
CVE-2025-15486MEDIUM4.4The Kunze Law plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's shortcode in all versions u...
CVE-2025-15377MEDIUM4.3The Sosh Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2025-15021MEDIUM4.4The Gotham Block Extra Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all...
CVE-2025-15020MEDIUM6.5The Gotham Block Extra Light plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and includ...
CVE-2025-14880MEDIUM5.3The Netcash WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a...
CVE-2025-14854MEDIUM5.4The WP-CRM System plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on the wpcr...
CVE-2025-14725MEDIUM4.4The Internal Link Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve...
CVE-2025-14482MEDIUM4.3The Crush.pics Image Optimizer - Image Compression and Optimization plugin for WordPress is vulnerable to unauthorized m...
CVE-2025-14464MEDIUM5.3The PDF Resume Parser plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in...
CVE-2025-14389MEDIUM4.3The WPBlogSyn plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. Th...
CVE-2025-14379MEDIUM4.4The Testimonials Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version...
CVE-2025-13627MEDIUM4.4The Makesweat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'makesweat_clubid' setting in al...
CVE-2025-12178MEDIUM6.4The SpiceForms Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'spiceforms' short...
CVE-2025-68970MEDIUM5.5Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulner...
CVE-2025-68969MEDIUM4.7Multi-thread race condition vulnerability in the thermal management module. Impact: Successful exploitation of this vuln...
CVE-2025-68967MEDIUM5.5Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now