2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-47330MEDIUM5.5Transient DOS while parsing video packets received from the video firmware.
CVE-2025-31964MEDIUM4.9Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged ...
CVE-2025-31962MEDIUM4.3Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authentic...
CVE-2025-15474MEDIUM5.3AuntyFey Smart Combination Lock firmware versions as of 2025-12-24 contain a vulnerability that allows an unauthenticate...
CVE-2025-15058MEDIUM6.4The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'table_currency' ...
CVE-2025-15000MEDIUM4.4The Page Keys plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘page_key’ parameter in all vers...
CVE-2025-14999MEDIUM4.3The Latest Tabs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2025-14904MEDIUM4.3The Newsletter Email Subscribe plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i...
CVE-2025-14901MEDIUM6.5The Bit Form – Contact Form Plugin plugin for WordPress is vulnerable to unauthorized workflow execution due to missing ...
CVE-2025-14891MEDIUM6.4The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'displayN...
CVE-2025-14888MEDIUM4.4The Simple User Meta Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user meta value fi...
CVE-2025-14887MEDIUM4.4The twinklesmtp – Email Service Provider For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2025-14875MEDIUM6.1The HBLPAY Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ...
CVE-2025-14867MEDIUM6.5The Flashcard plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.9 via the 'so...
CVE-2025-14845MEDIUM4.3The NS IE Compatibility Fixer plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up...
CVE-2025-14842MEDIUM6.1The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited upload of files wi...
CVE-2025-14802MEDIUM5.4The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to unauthorized file deletion in versions up to, and i...
CVE-2025-14796MEDIUM6.4The My Album Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image titles in all versions ...
CVE-2025-14792MEDIUM4.4The Key Figures plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the kf_field_figure_default_color_...
CVE-2025-14719MEDIUM4.9The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and es...
CVE-2025-14631MEDIUM6.5A NULL Pointer Dereference vulnerability in TP-Link Archer BE400 V1(802.11 modules) allows  an adjacent attacker to cau...
CVE-2025-14626MEDIUM6.4The QR Code for WooCommerce order emails, PDF invoices, packing slips plugin for WordPress is vulnerable to Stored Cross...
CVE-2025-14625MEDIUM6.7Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard on Windows (Nios II Command Shell module...
CVE-2025-14614MEDIUM6.7Insecure Temporary File vulnerability in Altera Quartus Prime Standard  Installer (SFX) on Windows, Altera Quartus Pr...
CVE-2025-14468MEDIUM4.3The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now