2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5329 | CRITICAL | 9.8 | 0.5% | Feb 4, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martcode Software ... |
| CVE-2025-15368 | HIGH | 8.8 | 0.8% | Feb 4, 2026 | The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 ... |
| CVE-2025-14740 | MEDIUM | 6.7 | 0.2% | Feb 4, 2026 | Docker Desktop for Windows contains multiple incorrect permission assignment vulnerabilities in the installer's handling... |
| CVE-2025-59818 | CRITICAL | 9.8 | 0.5% | Feb 4, 2026 | This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file ... |
| CVE-2025-41085 | MEDIUM | 5.1 | 0.2% | Feb 4, 2026 | Stored Cross-Site Scripting (XSS) vulnerability type in Apidog in the version 2.7.15, where SVG image uploads are not p... |
| CVE-2025-15508 | MEDIUM | 5.3 | 0.3% | Feb 4, 2026 | The Magic Import Document Extractor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions... |
| CVE-2025-15507 | MEDIUM | 5.3 | 0.3% | Feb 4, 2026 | The Magic Import Document Extractor plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2025-15487 | MEDIUM | 4.9 | 0.4% | Feb 4, 2026 | The Code Explorer plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.6 via t... |
| CVE-2025-15482 | MEDIUM | 5.3 | 0.3% | Feb 4, 2026 | The Chapa Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in... |
| CVE-2025-15285 | HIGH | 7.5 | 0.4% | Feb 4, 2026 | The SEO Flow by LupsOnline plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa... |
| CVE-2025-15268 | HIGH | 7.5 | 0.4% | Feb 4, 2026 | The Infility Global plugin for WordPress is vulnerable to unauthenticated SQL Injection via the 'infility_get_data' API ... |
| CVE-2025-15260 | MEDIUM | 6.5 | 0.3% | Feb 4, 2026 | The MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress is vulnerable to missing authorization i... |
| CVE-2025-14461 | MEDIUM | 5.3 | 0.3% | Feb 4, 2026 | The Xendit Payment plugin for WordPress is vulnerable to unauthorized order status manipulation in all versions up to, a... |
| CVE-2025-29867 | HIGH | 8.5 | 0.2% | Feb 4, 2026 | Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Hancom Inc. Hancom Office 2018, Hancom In... |
| CVE-2025-69621 | HIGH | 8.1 | 0.5% | Feb 4, 2026 | An arbitrary file overwrite vulnerability in the file import process of Comic Book Reader v1.0.95 allows attackers to ov... |
| CVE-2025-69620 | MEDIUM | 5 | 0.2% | Feb 4, 2026 | A path traversal in Moo Chan Song v4.5.7 allows attackers to cause a Denial of Service (DoS) via writing files to the in... |
| CVE-2025-36094 | HIGH | 8.1 | 0.2% | Feb 3, 2026 | IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and ... |
| CVE-2025-36033 | MEDIUM | 5.4 | 0.1% | Feb 3, 2026 | IBM Engineering Lifecycle Management - Global Configuration Management 7.0.3 through 7.0.3 Interim Fix 017, and 7.1.0 th... |
| CVE-2025-33081 | MEDIUM | 5.5 | 0.1% | Feb 3, 2026 | IBM Concert 1.0.0 through 2.1.0 stores potentially sensitive information in log files that could be read by a local user... |
| CVE-2025-65081 | MEDIUM | 6.9 | 0.5% | Feb 3, 2026 | An out-of-bounds read vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This v... |
| CVE-2025-65080 | MEDIUM | 6.9 | 0.5% | Feb 3, 2026 | A type confusion vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulner... |
| CVE-2025-65079 | MEDIUM | 6.9 | 0.5% | Feb 3, 2026 | A heap-based buffer overflow vulnerability has been identified in the Postscript interpreter in various Lexmark devices.... |
| CVE-2025-65078 | CRITICAL | 9.3 | 0.5% | Feb 3, 2026 | An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark device... |
| CVE-2025-65077 | HIGH | 8.8 | 0.6% | Feb 3, 2026 | A relative path traversal vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devic... |
| CVE-2025-64438 | HIGH | 7.5 | 0.5% | Feb 3, 2026 | Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now