2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67859 | MEDIUM | 5.1 | 0.2% | Jan 14, 2026 | A Improper Authentication vulnerability in TLP allows local users to arbitrarily control the power profile in use as wel... |
| CVE-2025-66169 | MEDIUM | 5.3 | 0.6% | Jan 14, 2026 | Cypher Injection vulnerability in Apache Camel camel-neo4j component. This issue affects Apache Camel: from 4.10.0 befo... |
| CVE-2025-68492 | MEDIUM | 4.2 | 0.2% | Jan 14, 2026 | Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vuln... |
| CVE-2025-15513 | MEDIUM | 5.3 | 0.2% | Jan 14, 2026 | The Float Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to improper error ... |
| CVE-2025-15512 | MEDIUM | 5.3 | 0.2% | Jan 14, 2026 | The Aplazo Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa... |
| CVE-2025-15475 | MEDIUM | 5.3 | 0.2% | Jan 14, 2026 | The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of da... |
| CVE-2025-15376 | MEDIUM | 4.3 | 0.1% | Jan 14, 2026 | The Stopwords for comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2025-14846 | MEDIUM | 4.3 | 0.1% | Jan 14, 2026 | The SocialChamp with WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a... |
| CVE-2025-14173 | MEDIUM | 5.3 | 0.2% | Jan 14, 2026 | The Perfit WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,... |
| CVE-2025-15486 | MEDIUM | 4.4 | 0.2% | Jan 14, 2026 | The Kunze Law plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's shortcode in all versions u... |
| CVE-2025-15377 | MEDIUM | 4.3 | 0.1% | Jan 14, 2026 | The Sosh Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2025-15021 | MEDIUM | 4.4 | 0.2% | Jan 14, 2026 | The Gotham Block Extra Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all... |
| CVE-2025-15020 | MEDIUM | 6.5 | 0.3% | Jan 14, 2026 | The Gotham Block Extra Light plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and includ... |
| CVE-2025-14880 | MEDIUM | 5.3 | 0.2% | Jan 14, 2026 | The Netcash WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a... |
| CVE-2025-14854 | MEDIUM | 5.4 | 0.2% | Jan 14, 2026 | The WP-CRM System plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on the wpcr... |
| CVE-2025-14725 | MEDIUM | 4.4 | 0.2% | Jan 14, 2026 | The Internal Link Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve... |
| CVE-2025-14482 | MEDIUM | 4.3 | 0.3% | Jan 14, 2026 | The Crush.pics Image Optimizer - Image Compression and Optimization plugin for WordPress is vulnerable to unauthorized m... |
| CVE-2025-14464 | MEDIUM | 5.3 | 0.3% | Jan 14, 2026 | The PDF Resume Parser plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in... |
| CVE-2025-14389 | MEDIUM | 4.3 | 0.1% | Jan 14, 2026 | The WPBlogSyn plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. Th... |
| CVE-2025-14379 | MEDIUM | 4.4 | 0.2% | Jan 14, 2026 | The Testimonials Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version... |
| CVE-2025-13627 | MEDIUM | 4.4 | 0.2% | Jan 14, 2026 | The Makesweat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'makesweat_clubid' setting in al... |
| CVE-2025-12178 | MEDIUM | 6.4 | 0.2% | Jan 14, 2026 | The SpiceForms Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'spiceforms' short... |
| CVE-2025-68970 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulner... |
| CVE-2025-68969 | MEDIUM | 4.7 | 0.1% | Jan 14, 2026 | Multi-thread race condition vulnerability in the thermal management module. Impact: Successful exploitation of this vuln... |
| CVE-2025-68967 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now