2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14369 | MEDIUM | 5.5 | 0.1% | Jan 20, 2026 | dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting th... |
| CVE-2025-41084 | MEDIUM | 5.1 | 0.3% | Jan 20, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in Sesame web application, due to the fact that uploaded SVG images are ... |
| CVE-2025-14533 | CRITICAL | 9.8 | 1.0% | Jan 20, 2026 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, a... |
| CVE-2025-41768 | MEDIUM | 5.5 | 0.2% | Jan 20, 2026 | An high privileged remote attacker can inject arbitrary content into the custom CSS field on the affected devices due to... |
| CVE-2025-66523 | MEDIUM | 6.1 | 0.2% | Jan 20, 2026 | URL parameters are directly embedded into JavaScript code or HTML attributes without proper encoding or sanitization. Th... |
| CVE-2025-12573 | MEDIUM | 6.5 | 0.2% | Jan 20, 2026 | The Bookingor WordPress plugin through 1.0.12 exposes authenticated AJAX actions without capability or nonce checks, al... |
| CVE-2025-14977 | HIGH | 8.1 | 0.3% | Jan 20, 2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPr... |
| CVE-2025-14348 | MEDIUM | 5.3 | 0.3% | Jan 20, 2026 | The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for Wo... |
| CVE-2025-14798 | MEDIUM | 5.3 | 0.2% | Jan 20, 2026 | The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, a... |
| CVE-2025-14351 | MEDIUM | 5.3 | 0.2% | Jan 20, 2026 | The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to unauthorized loss of data due to a miss... |
| CVE-2025-14978 | MEDIUM | 5.3 | 0.2% | Jan 20, 2026 | The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) plugin for W... |
| CVE-2025-15466 | MEDIUM | 5.4 | 0.2% | Jan 20, 2026 | The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to unauthorized access and modification of d... |
| CVE-2025-69199 | MEDIUM | 6.5 | 0.3% | Jan 19, 2026 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.... |
| CVE-2025-69198 | MEDIUM | 6.5 | 0.2% | Jan 19, 2026 | Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to ... |
| CVE-2025-55252 | CRITICAL | 9.8 | 0.1% | Jan 19, 2026 | HCL AION version 2 is affected by a Weak Password Policy vulnerability. This can allow the use of easily guessable pas... |
| CVE-2025-55250 | MEDIUM | 5.3 | 0.1% | Jan 19, 2026 | HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical detail... |
| CVE-2025-55251 | CRITICAL | 9.8 | 0.2% | Jan 19, 2026 | HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re... |
| CVE-2025-55249 | MEDIUM | 5.3 | 0.2% | Jan 19, 2026 | HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may ... |
| CVE-2025-52661 | MEDIUM | 5.3 | 0.1% | Jan 19, 2026 | HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse,... |
| CVE-2025-52660 | CRITICAL | 9.8 | 0.3% | Jan 19, 2026 | HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re... |
| CVE-2025-52659 | HIGH | 7.5 | 0.2% | Jan 19, 2026 | HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensit... |
| CVE-2025-68616 | HIGH | 7.5 | 0.5% | Jan 19, 2026 | WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) pro... |
| CVE-2025-61684 | HIGH | 7.5 | 0.3% | Jan 19, 2026 | Quicly, an IETF QUIC protocol implementation, is susceptible to a denial-of-service attack prior to commit d9d3df6a8530a... |
| CVE-2025-11044 | HIGH | 8.9 | 0.3% | Jan 19, 2026 | An Allocation of Resources Without Limits or Throttling vulnerability in the ANSL-Server component of B&R Automation Run... |
| CVE-2025-11043 | CRITICAL | 9.1 | 0.2% | Jan 19, 2026 | An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL over TLS client used in Automation Studio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now