2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13935MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course completio...
CVE-2025-13934MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course enrollmen...
CVE-2025-13753MEDIUM4.3The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2025-13628MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification and...
CVE-2025-15019MEDIUM6.4The BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce plugin for WordPress is vulnerabl...
CVE-2025-14980MEDIUM6.5The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including...
CVE-2025-14893MEDIUM6.4The IndieWeb plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Telephone' parameter in all vers...
CVE-2025-14782MEDIUM5.3The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to authorizat...
CVE-2025-14720MEDIUM5.3The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due ...
CVE-2025-14718MEDIUM5.4The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to authorization bypass in all ver...
CVE-2025-14574MEDIUM5.3The weDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2....
CVE-2025-14803MEDIUM6.8The NEX-Forms WordPress plugin before 9.1.8 does not sanitise and escape some of its settings. The NEX-Forms WordPress...
CVE-2025-13749MEDIUM4.3The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cr...
CVE-2025-14886MEDIUM5.3The Japanized for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...
CVE-2025-68718MEDIUM5.4KAYSUS KS-WR1200 routers with firmware 107 expose SSH and TELNET services on the LAN interface with hardcoded root crede...
CVE-2025-14505MEDIUM5.6The ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of 'k' (as computed ...
CVE-2025-65731MEDIUM6.8An issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacke...
CVE-2025-67825MEDIUM5.5An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information...
CVE-2025-61550MEDIUM5.4Cross-Site Scripting (XSS) is present on the ctl00_Content01_fieldValue parameters on the /psp/appNet/TemplateOrder/Temp...
CVE-2025-61549MEDIUM6.1Cross-Site Scripting (XSS) is present on the LoginID parameter on the /PSP/app/web/reg/reg_display.asp endpoint in edu B...
CVE-2025-61547MEDIUM6.8Cross-Site Request Forgery (CSRF) is present on all functions in edu Business Solutions Print Shop Pro WebDesk version 1...
CVE-2025-67091MEDIUM6.5An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL....
CVE-2025-67090MEDIUM5.1The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL...
CVE-2025-67603MEDIUM5.1A Improper Authorization vulnerability in Foomuuri llows arbitrary users to influence the firewall configuration.This is...
CVE-2025-66002MEDIUM6.9An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability allows local users ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now