2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61140 | CRITICAL | 9.8 | 0.4% | Jan 28, 2026 | The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution. |
| CVE-2025-58150 | HIGH | 8.8 | 0.1% | Jan 28, 2026 | Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables... |
| CVE-2025-57283 | HIGH | 7.8 | 0.7% | Jan 28, 2026 | The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile... |
| CVE-2025-14795 | MEDIUM | 4.3 | 0.2% | Jan 28, 2026 | The Stop Spammers Classic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-14865 | MEDIUM | 6.4 | 0.2% | Jan 28, 2026 | The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2025-59901 | HIGH | 8.5 | 0.2% | Jan 28, 2026 | Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoin... |
| CVE-2025-59900 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ... |
| CVE-2025-59899 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ... |
| CVE-2025-59898 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ... |
| CVE-2025-59897 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ... |
| CVE-2025-59896 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ... |
| CVE-2025-59895 | HIGH | 7.5 | 0.4% | Jan 28, 2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a remote denial-of-service (DoS) vulne... |
| CVE-2025-59894 | HIGH | 8 | 0.1% | Jan 28, 2026 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.... |
| CVE-2025-59893 | HIGH | 8 | 0.1% | Jan 28, 2026 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.... |
| CVE-2025-59892 | HIGH | 8 | 0.1% | Jan 28, 2026 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.... |
| CVE-2025-59891 | HIGH | 8 | 0.1% | Jan 28, 2026 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.... |
| CVE-2025-26386 | HIGH | 7.1 | 0.4% | Jan 28, 2026 | Johnson Controls iSTAR Configuration Utility (ICU) has Stack-based Buffer Overflow vulnerability. This issue affects iST... |
| CVE-2025-15511 | MEDIUM | 5.3 | 0.2% | Jan 28, 2026 | The Rupantorpay plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec... |
| CVE-2025-14616 | MEDIUM | 4.3 | 0.1% | Jan 28, 2026 | The Recooty – Job Widget (Old Dashboard) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version... |
| CVE-2025-14386 | HIGH | 8.8 | 0.4% | Jan 28, 2026 | The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress ... |
| CVE-2025-14283 | MEDIUM | 6.4 | 0.2% | Jan 28, 2026 | The BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library plugin ... |
| CVE-2025-14063 | MEDIUM | 6.1 | 0.2% | Jan 28, 2026 | The SEO Links Interlinking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'google_error' p... |
| CVE-2025-41351 | MEDIUM | 6 | 0.2% | Jan 28, 2026 | Vulnerability that allows a Padding Oracle Attack to be performed on the Funambol v30.0.0.20 cloud server. The thumbnail... |
| CVE-2025-7740 | HIGH | 8.8 | 0.2% | Jan 28, 2026 | Default credentials vulnerability exists in SuprOS product. If exploited, this could allow an authenticated local attack... |
| CVE-2025-40554 | CRITICAL | 9.8 | 58.4% | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now