2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14631 | MEDIUM | 6.5 | 0.2% | Jan 7, 2026 | A NULL Pointer Dereference vulnerability in TP-Link Archer BE400 V1(802.11 modules) allows an adjacent attacker to cau... |
| CVE-2025-14626 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The QR Code for WooCommerce order emails, PDF invoices, packing slips plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2025-14625 | MEDIUM | 6.7 | 0.1% | Jan 7, 2026 | Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard on Windows (Nios II Command Shell module... |
| CVE-2025-14614 | MEDIUM | 6.7 | 0.1% | Jan 7, 2026 | Insecure Temporary File vulnerability in Altera Quartus Prime Standard Installer (SFX) on Windows, Altera Quartus Pr... |
| CVE-2025-14468 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u... |
| CVE-2025-14465 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The Sticky Action Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-14460 | MEDIUM | 5.3 | 0.4% | Jan 7, 2026 | The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized order status modificatio... |
| CVE-2025-14453 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The My Album Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style_css' shortcode att... |
| CVE-2025-14370 | MEDIUM | 4.3 | 0.2% | Jan 7, 2026 | The Quote Comments plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0... |
| CVE-2025-14352 | MEDIUM | 5.3 | 0.2% | Jan 7, 2026 | The Awesome Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to incorrect autho... |
| CVE-2025-14147 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Easy GitHub Gist Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter... |
| CVE-2025-14145 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Niche Hero | Beautifully-designed blocks in seconds plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2025-14144 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Mstoic Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'start' parameter of the... |
| CVE-2025-14131 | MEDIUM | 6.1 | 0.3% | Jan 7, 2026 | The WP Widget Changer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']... |
| CVE-2025-14130 | MEDIUM | 6.1 | 0.3% | Jan 7, 2026 | The Post Like Dislike plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']... |
| CVE-2025-14128 | MEDIUM | 6.1 | 0.3% | Jan 7, 2026 | The Stumble! for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_S... |
| CVE-2025-14127 | MEDIUM | 6.1 | 0.3% | Jan 7, 2026 | The Testimonial Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF'... |
| CVE-2025-14122 | MEDIUM | 6.4 | 0.3% | Jan 7, 2026 | The AD Sliding FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliding_faq' shortcode in ... |
| CVE-2025-14121 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The EDD Download Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'edd_download_info_link'... |
| CVE-2025-14118 | MEDIUM | 6.1 | 0.3% | Jan 7, 2026 | The Starred Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the PHP_SELF variable in all... |
| CVE-2025-14114 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The 1180px Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attrib... |
| CVE-2025-14113 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Viitor Button Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' shortcode ... |
| CVE-2025-14112 | MEDIUM | 6.4 | 0.3% | Jan 7, 2026 | The Snillrik Restaurant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'menu_style' shortcode... |
| CVE-2025-14110 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The WP Js List Pages Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortc... |
| CVE-2025-14109 | MEDIUM | 6.4 | 0.3% | Jan 7, 2026 | The AH Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'column' shortcode attribute... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now