2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15564 | MEDIUM | 5.5 | 0.2% | Feb 7, 2026 | A vulnerability has been found in Mapnik up to 4.2.0. This vulnerability affects the function mapnik::detail::mod<...>::... |
| CVE-2025-15477 | MEDIUM | 6.5 | 0.2% | Feb 7, 2026 | The Bucketlister plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode `category` and `id` attr... |
| CVE-2025-15476 | MEDIUM | 4.3 | 0.2% | Feb 7, 2026 | The The Bucketlister plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2025-15491 | MEDIUM | 5.5 | 0.3% | Feb 7, 2026 | The Post Slides WordPress plugin through 1.0.1 does not validate some shortcode attributes before using them to generate... |
| CVE-2025-15267 | MEDIUM | 6.4 | 0.2% | Feb 7, 2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_accordion... |
| CVE-2025-13463 | MEDIUM | 6.4 | 0.2% | Feb 7, 2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Grid component in a... |
| CVE-2025-12803 | MEDIUM | 6.4 | 0.2% | Feb 7, 2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bt_bb_tabs' shor... |
| CVE-2025-12159 | MEDIUM | 6.4 | 0.2% | Feb 7, 2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_raw_conte... |
| CVE-2025-31990 | MEDIUM | 6.8 | 0.3% | Feb 7, 2026 | Rate limiting for certain API calls is not being enforced, making HCL Velocity vulnerable to Denial of Service (DoS) att... |
| CVE-2025-68621 | HIGH | 7.4 | 0.5% | Feb 6, 2026 | Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large person... |
| CVE-2025-15320 | LOW | 3.3 | 0.1% | Feb 6, 2026 | Tanium addressed a denial of service vulnerability in Tanium Client. |
| CVE-2025-69216 | MEDIUM | 6.5 | 0.4% | Feb 6, 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an au... |
| CVE-2025-69214 | HIGH | 8.8 | 0.4% | Feb 6, 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an SQ... |
| CVE-2025-69212 | HIGH | 8.8 | 1.8% | Feb 6, 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a cri... |
| CVE-2025-70963 | HIGH | 7.6 | 0.3% | Feb 6, 2026 | Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived ... |
| CVE-2025-64175 | HIGH | 8.8 | 0.4% | Feb 6, 2026 | Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not... |
| CVE-2025-64111 | CRITICAL | 9.8 | 1.2% | Feb 6, 2026 | Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-... |
| CVE-2025-13523 | MEDIUM | 5.4 | 0.2% | Feb 6, 2026 | Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rend... |
| CVE-2025-13818 | MEDIUM | 6.7 | 0.1% | Feb 6, 2026 | Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent |
| CVE-2025-10753 | MEDIUM | 5.3 | 0.3% | Feb 6, 2026 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to unauthorized access in all versions ... |
| CVE-2025-15566 | HIGH | 8.8 | 0.5% | Feb 6, 2026 | A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress ... |
| CVE-2025-68458 | LOW | 3.7 | 0.2% | Feb 5, 2026 | Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTT... |
| CVE-2025-68157 | LOW | 3.7 | 0.2% | Feb 5, 2026 | Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTT... |
| CVE-2025-32393 | MEDIUM | 6.5 | 0.4% | Feb 5, 2026 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut... |
| CVE-2025-12131 | MEDIUM | 6.5 | 0.2% | Feb 5, 2026 | A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now