2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40553 | CRITICAL | 9.8 | 60.4% | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead ... |
| CVE-2025-40552 | CRITICAL | 9.8 | 49.7% | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would ... |
| CVE-2025-40551 | CRITICAL | 9.8 | 84.1% | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead ... |
| CVE-2025-40537 | HIGH | 7.5 | 0.5% | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situat... |
| CVE-2025-40536 | CRITICAL | 9.8 | 81.6% | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could... |
| CVE-2025-9082 | MEDIUM | 6.4 | 0.3% | Jan 28, 2026 | The WPBITS Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widget pa... |
| CVE-2025-14039 | MEDIUM | 6.4 | 0.3% | Jan 28, 2026 | The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_simple_folio_item_client_na... |
| CVE-2025-12709 | MEDIUM | 6.4 | 0.2% | Jan 28, 2026 | The Interactions – Create Interactive Experiences in the Block Editor plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2025-8072 | MEDIUM | 6.4 | 0.2% | Jan 28, 2026 | The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder_img... |
| CVE-2025-14610 | HIGH | 7.2 | 0.3% | Jan 28, 2026 | The TableMaster for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a... |
| CVE-2025-13471 | MEDIUM | 5.3 | 0.3% | Jan 28, 2026 | The User Activity Log WordPress plugin through 2.2 does not properly handle failed login attempts in some cases, allowin... |
| CVE-2025-67645 | HIGH | 8.8 | 0.3% | Jan 28, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ... |
| CVE-2025-55292 | HIGH | 8.2 | 0.1% | Jan 28, 2026 | Meshtastic is an open source mesh networking solution. In the current Meshtastic architecture, a Node is identified by t... |
| CVE-2025-54373 | MEDIUM | 6.5 | 0.4% | Jan 28, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ... |
| CVE-2025-21589 | CRITICAL | 9.8 | 1.4% | Jan 27, 2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may a... |
| CVE-2025-14988 | CRITICAL | 10 | 0.4% | Jan 27, 2026 | A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain co... |
| CVE-2025-12810 | MEDIUM | 6.5 | 0.4% | Jan 27, 2026 | Improper Authentication vulnerability in Delinea Inc. Secret Server On-Prem (RPC Password Rotation modules).This issue a... |
| CVE-2025-33234 | HIGH | 7.8 | 0.2% | Jan 27, 2026 | NVIDIA runx contains a vulnerability where an attacker could cause a code injection. A successful exploit of this vulner... |
| CVE-2025-14911 | HIGH | 7.1 | 0.3% | Jan 27, 2026 | User-controlled chunkSize metadata from MongoDB lacks appropriate validation allowing malformed GridFS metadata to overf... |
| CVE-2025-69564 | CRITICAL | 9.8 | 0.4% | Jan 27, 2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Addres... |
| CVE-2025-69563 | CRITICAL | 9.8 | 0.4% | Jan 27, 2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password paramete... |
| CVE-2025-69562 | CRITICAL | 9.8 | 0.4% | Jan 27, 2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /insertmessage.php via the userid para... |
| CVE-2025-69559 | CRITICAL | 9.8 | 0.5% | Jan 27, 2026 | code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php. |
| CVE-2025-65264 | MEDIUM | 5.5 | 0.2% | Jan 27, 2026 | The kernel driver of CPUID CPU-Z v2.17 and earlier does not validate user-supplied values passed via its IOCTL interface... |
| CVE-2025-69565 | CRITICAL | 9.8 | 0.4% | Jan 27, 2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now