2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13851 | CRITICAL | 9.8 | 0.3% | Feb 19, 2026 | The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user re... |
| CVE-2025-13563 | CRITICAL | 9.8 | 0.4% | Feb 19, 2026 | The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3... |
| CVE-2025-12882 | CRITICAL | 9.8 | 0.4% | Feb 19, 2026 | The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. ... |
| CVE-2025-70152 | CRITICAL | 9.8 | 0.4% | Feb 18, 2026 | code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management... |
| CVE-2025-70150 | CRITICAL | 9.8 | 0.6% | Feb 18, 2026 | CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that al... |
| CVE-2025-14009 | CRITICAL | 10 | 0.8% | Feb 18, 2026 | A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter f... |
| CVE-2025-70149 | CRITICAL | 9.8 | 0.4% | Feb 18, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parame... |
| CVE-2025-70146 | CRITICAL | 9.1 | 0.5% | Feb 18, 2026 | Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Genera... |
| CVE-2025-70141 | CRITICAL | 9.4 | 0.5% | Feb 18, 2026 | SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX disp... |
| CVE-2025-70998 | CRITICAL | 9.8 | 0.4% | Feb 18, 2026 | UTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was discovered to contain insecure default credentials for the tel... |
| CVE-2025-65791 | CRITICAL | 9.8 | 1.6% | Feb 18, 2026 | ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user i... |
| CVE-2025-15579 | CRITICAL | 9.5 | 0.3% | Feb 18, 2026 | Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection. The vulnerabi... |
| CVE-2025-33089 | CRITICAL | 9.8 | 0.2% | Feb 17, 2026 | IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized ac... |
| CVE-2025-66614 | CRITICAL | 9.1 | 0.2% | Feb 17, 2026 | Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-... |
| CVE-2025-59793 | CRITICAL | 9.9 | 1.0% | Feb 17, 2026 | Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authentica... |
| CVE-2025-70830 | CRITICAL | 9.9 | 1.0% | Feb 17, 2026 | A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows aut... |
| CVE-2025-15578 | CRITICAL | 9.8 | 0.3% | Feb 16, 2026 | Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the sys... |
| CVE-2025-32058 | CRITICAL | 9.3 | 0.2% | Feb 15, 2026 | The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment... |
| CVE-2025-8572 | CRITICAL | 9.8 | 0.4% | Feb 14, 2026 | The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7... |
| CVE-2025-69633 | CRITICAL | 9.8 | 0.4% | Feb 13, 2026 | A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through ... |
| CVE-2025-69770 | CRITICAL | 10 | 0.6% | Feb 13, 2026 | A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execu... |
| CVE-2025-70314 | CRITICAL | 9.8 | 0.4% | Feb 12, 2026 | webfsd 1.21 is vulnerable to a Buffer Overflow via a crafted request. This is due to the filename variable |
| CVE-2025-70981 | CRITICAL | 9.8 | 0.3% | Feb 12, 2026 | CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds p... |
| CVE-2025-69634 | CRITICAL | 9 | 0.1% | Feb 12, 2026 | Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges ... |
| CVE-2025-14014 | CRITICAL | 9.8 | 0.4% | Feb 12, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software H... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now