2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13935 | MEDIUM | 4.3 | 0.2% | Jan 9, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course completio... |
| CVE-2025-13934 | MEDIUM | 4.3 | 0.2% | Jan 9, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course enrollmen... |
| CVE-2025-13753 | MEDIUM | 4.3 | 0.2% | Jan 9, 2026 | The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to unauthorized modification of data... |
| CVE-2025-13628 | MEDIUM | 4.3 | 0.2% | Jan 9, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification and... |
| CVE-2025-15019 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce plugin for WordPress is vulnerabl... |
| CVE-2025-14980 | MEDIUM | 6.5 | 0.3% | Jan 9, 2026 | The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including... |
| CVE-2025-14893 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The IndieWeb plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Telephone' parameter in all vers... |
| CVE-2025-14782 | MEDIUM | 5.3 | 0.3% | Jan 9, 2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to authorizat... |
| CVE-2025-14720 | MEDIUM | 5.3 | 0.3% | Jan 9, 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due ... |
| CVE-2025-14718 | MEDIUM | 5.4 | 0.3% | Jan 9, 2026 | The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to authorization bypass in all ver... |
| CVE-2025-14574 | MEDIUM | 5.3 | 0.3% | Jan 9, 2026 | The weDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.... |
| CVE-2025-14803 | MEDIUM | 6.8 | 0.2% | Jan 9, 2026 | The NEX-Forms WordPress plugin before 9.1.8 does not sanitise and escape some of its settings. The NEX-Forms WordPress... |
| CVE-2025-13749 | MEDIUM | 4.3 | 0.1% | Jan 9, 2026 | The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cr... |
| CVE-2025-14886 | MEDIUM | 5.3 | 0.2% | Jan 9, 2026 | The Japanized for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2025-68718 | MEDIUM | 5.4 | 0.3% | Jan 8, 2026 | KAYSUS KS-WR1200 routers with firmware 107 expose SSH and TELNET services on the LAN interface with hardcoded root crede... |
| CVE-2025-14505 | MEDIUM | 5.6 | 0.2% | Jan 8, 2026 | The ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of 'k' (as computed ... |
| CVE-2025-65731 | MEDIUM | 6.8 | 0.4% | Jan 8, 2026 | An issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacke... |
| CVE-2025-67825 | MEDIUM | 5.5 | 0.1% | Jan 8, 2026 | An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information... |
| CVE-2025-61550 | MEDIUM | 5.4 | 0.2% | Jan 8, 2026 | Cross-Site Scripting (XSS) is present on the ctl00_Content01_fieldValue parameters on the /psp/appNet/TemplateOrder/Temp... |
| CVE-2025-61549 | MEDIUM | 6.1 | 0.2% | Jan 8, 2026 | Cross-Site Scripting (XSS) is present on the LoginID parameter on the /PSP/app/web/reg/reg_display.asp endpoint in edu B... |
| CVE-2025-61547 | MEDIUM | 6.8 | 0.1% | Jan 8, 2026 | Cross-Site Request Forgery (CSRF) is present on all functions in edu Business Solutions Print Shop Pro WebDesk version 1... |
| CVE-2025-67091 | MEDIUM | 6.5 | 3.0% | Jan 8, 2026 | An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL.... |
| CVE-2025-67090 | MEDIUM | 5.1 | 0.2% | Jan 8, 2026 | The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL... |
| CVE-2025-67603 | MEDIUM | 5.1 | 0.1% | Jan 8, 2026 | A Improper Authorization vulnerability in Foomuuri llows arbitrary users to influence the firewall configuration.This is... |
| CVE-2025-66002 | MEDIUM | 6.9 | 0.1% | Jan 8, 2026 | An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability allows local users ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now