2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70073 | HIGH | 7.2 | 0.7% | Feb 5, 2026 | An issue in ChestnutCMS v.1.5.8 and before allows a remote attacker to execute arbitrary code via the template creation ... |
| CVE-2025-68121 | CRITICAL | 10 | 0.8% | Feb 5, 2026 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th... |
| CVE-2025-58190 | MEDIUM | 5.3 | 0.5% | Feb 5, 2026 | The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can ... |
| CVE-2025-47911 | MEDIUM | 5.3 | 0.5% | Feb 5, 2026 | The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which ... |
| CVE-2025-15557 | HIGH | 8.8 | 0.2% | Feb 5, 2026 | An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on ... |
| CVE-2025-15551 | MEDIUM | 5.6 | 0.4% | Feb 5, 2026 | The response coming from TP-Link Archer MR200 v5.2, C20 v5 and v6, TL-WR850N v3, and TL-WR845N v4 for any request is get... |
| CVE-2025-70792 | MEDIUM | 6.1 | 0.3% | Feb 5, 2026 | Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipu... |
| CVE-2025-70791 | MEDIUM | 6.1 | 0.3% | Feb 5, 2026 | Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipu... |
| CVE-2025-69906 | HIGH | 8.8 | 0.7% | Feb 5, 2026 | Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies o... |
| CVE-2025-69619 | MEDIUM | 5.5 | 0.2% | Feb 5, 2026 | A path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the i... |
| CVE-2025-68723 | CRITICAL | 9 | 0.3% | Feb 5, 2026 | Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin in... |
| CVE-2025-68643 | MEDIUM | 5.4 | 0.2% | Feb 5, 2026 | Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account pre... |
| CVE-2025-68722 | HIGH | 8.8 | 0.2% | Feb 5, 2026 | Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability i... |
| CVE-2025-68721 | HIGH | 8.1 | 0.3% | Feb 5, 2026 | Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegat... |
| CVE-2025-14150 | MEDIUM | 6.5 | 0.3% | Feb 5, 2026 | IBM webMethods Integration (on prem) - Integration Server 10.15 through IS_10.15_Core_Fix2411.1 to IS_11.1_Core_Fix8 IBM... |
| CVE-2025-13491 | MEDIUM | 5.1 | 0.1% | Feb 5, 2026 | IBM App Connect Enterprise Certified Container CD: 11.2.0 through 11.6.0, 12.1.0 through 12.19.0 and 12.0 LTS: 12.0.0 th... |
| CVE-2025-13379 | HIGH | 8.6 | 0.4% | Feb 5, 2026 | IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ... |
| CVE-2025-14079 | MEDIUM | 5.3 | 0.3% | Feb 5, 2026 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in a... |
| CVE-2025-13416 | MEDIUM | 4.3 | 0.3% | Feb 5, 2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspensi... |
| CVE-2025-10258 | MEDIUM | 6.3 | 0.3% | Feb 5, 2026 | Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may r... |
| CVE-2025-15080 | HIGH | 8.8 | 0.5% | Feb 5, 2026 | Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric MELSEC iQ-R Series R08PCPU, R16P... |
| CVE-2025-61732 | HIGH | 8.6 | 0.5% | Feb 5, 2026 | A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. |
| CVE-2025-10314 | HIGH | 8.8 | 0.1% | Feb 5, 2026 | Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation FREQSHIP-mini for Windows versions 8.0.0 ... |
| CVE-2025-11730 | HIGH | 7.2 | 1.4% | Feb 5, 2026 | A post‑authentication command injection vulnerability in the Dynamic DNS (DDNS) configuration CLI command in Zyxel ATP s... |
| CVE-2025-13192 | HIGH | 8.2 | 0.4% | Feb 5, 2026 | The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now