CVE Vulnerabilities in 2025

2,200 documented vulnerabilities published in 2025.

Other years: 2026 2024 2023 2022 2021 2020

Top Affected Vendors in 2025

All CVEs from 2025

CVE-2025-68977
6.1 medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes DesignThemes Portfolio Addon designthemes-portfolio-addon allows DOM-Based XSS.This issue affects DesignThemes Portfolio Addon: from n/a through <= 1.5.

Dec 30, 2025
CVE-2025-68976
8.8 high

Missing Authorization vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eagle Booking: from n/a through <= 1.3.4.3.

Dec 30, 2025
CVE-2025-68975
8.1 high

Authorization Bypass Through User-Controlled Key vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eagle Booking: from n/a through <= 1.3.4.3.

Dec 30, 2025
CVE-2025-68974
9.8 critical

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and Register miniorange-login-openid allows PHP Local File Inclusion.This issue affects WordPress Social Login and Register: from n/a through <=

Dec 30, 2025
CVE-2025-15245
3.5 low

A vulnerability was found in D-Link DCS-850L 1.02.09. Affected is the function uploadfirmware of the component Firmware Update Service. The manipulation of the argument DownloadFile results in path traversal. The attack must originate from the local network. The exploit has been made public and coul

Dlink Dcs-850L Firmware Dec 30, 2025
CVE-2025-15244
3.7 low

A vulnerability has been found in PHPEMS up to 11.0. This impacts an unknown function of the component Purchase Request Handler. The manipulation leads to race condition. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is said to be diff

Phpems Phpems Dec 30, 2025
CVE-2025-15359
9.1 critical

DVP-12SE11T - Out-of-bound memory write Vulnerability

Deltaww Dvp-12Se11T Firmware Dec 30, 2025
CVE-2025-15243
7.3 high

A flaw has been found in code-projects Simple Stock System 1.0. This affects an unknown function of the file /market/login.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.

Carmelo Simple Stock System Dec 30, 2025
CVE-2025-15242
3.1 low

A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function of the component Coupon Handler. Performing a manipulation results in race condition. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is regarded as dif

Phpems Phpems Dec 30, 2025
CVE-2025-15358
7.5 high

DVP-12SE11T - Denial of Service Vulnerability

Deltaww Dvp-12Se11T Firmware Dec 30, 2025
CVE-2025-15241
3.5 low

A security vulnerability has been detected in CloudPanel Community Edition up to 2.5.1. The affected element is an unknown function of the file /admin/users of the component HTTP Header Handler. Such manipulation of the argument Referer leads to open redirect. It is possible to launch the attack rem

Dec 30, 2025
CVE-2025-15234
8.8 high

A weakness has been identified in Tenda M3 1.0.0.13(4903). Impacted is the function formSetRemoteInternetLanInfo of the file /goform/setInternetLanInfo. This manipulation of the argument portIp/portMask/portGateWay/portDns/portSecDns causes heap-based buffer overflow. It is possible to initiate the

Tenda M3 Firmware Dec 30, 2025
CVE-2025-15103
8.1 high

DVP-12SE11T - Authentication Bypass via Partial Password Disclosure

Deltaww Dvp-12Se11T Firmware Dec 30, 2025
CVE-2025-15102
9.1 critical

DVP-12SE11T - Password Protection Bypass

Deltaww Dvp-12Se11T Firmware Dec 30, 2025
CVE-2025-15355
6.1 medium

ISOinsight developed by NetVision Information has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

Dec 30, 2025
CVE-2025-15233
8.8 high

A security flaw has been discovered in Tenda M3 1.0.0.13(4903). This issue affects the function formSetAdInfoDetails of the file /goform/setAdInfoDetail. The manipulation of the argument adName/smsPassword/smsAccount/weixinAccount/weixinName/smsSignature/adRedirectUrl/adCopyRight/smsContent/adItemUI

Tenda M3 Firmware Dec 30, 2025
CVE-2025-15232
8.8 high

A vulnerability was identified in Tenda M3 1.0.0.13(4903). This vulnerability affects the function formSetAdPushInfo of the file /goform/setAdPushInfo. The manipulation of the argument mac/terminal leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit i

Tenda M3 Firmware Dec 30, 2025
CVE-2025-15231
8.8 high

A vulnerability was determined in Tenda M3 1.0.0.13(4903). This affects the function formSetRemoteVlanInfo of the file /goform/setVlanInfo. Executing a manipulation of the argument ID/vlan/port can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicl

Tenda M3 Firmware Dec 30, 2025
CVE-2025-15230
8.8 high

A vulnerability was found in Tenda M3 1.0.0.13(4903). Affected by this issue is the function formSetVlanPolicy of the file /goform/setVlanPolicyData. Performing a manipulation of the argument qvlan_truck_port results in heap-based buffer overflow. Remote exploitation of the attack is possible. The e

Tenda M3 Firmware Dec 30, 2025
CVE-2025-15229
5.3 medium

A vulnerability has been found in Tenda CH22 up to 1.0.0.1. Affected by this vulnerability is the function fromDhcpListClient of the file /goform/DhcpListClient. Such manipulation of the argument LISTLEN leads to denial of service. The attack may be launched remotely. The exploit has been disclosed

Tenda Ch22 Firmware Dec 30, 2025
CVE-2025-15222
5.0 medium

A vulnerability has been found in Dromara Sa-Token up to 1.44.0. This issue affects the function ObjectInputStream.readObject of the file SaSerializerTemplateForJdkUseBase64.java. Such manipulation leads to deserialization. The attack can be executed remotely. This attack is characterized by high co

Dec 30, 2025
CVE-2025-14313
6.1 medium

The Advance WP Query Search Filter WordPress plugin through 1.0.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Dec 30, 2025
CVE-2025-14312
6.1 medium

The Advance WP Query Search Filter WordPress plugin through 1.0.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Dec 30, 2025
CVE-2025-15221
3.5 low

A flaw has been found in SohuTV CacheCloud up to 3.2.0. This vulnerability affects the function index of the file src/main/java/com/sohu/cache/web/controller/AppDataMigrateController.java. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. The exploit has b

Sohu Cachecloud Dec 30, 2025