2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14450 | MEDIUM | 6.5 | 0.2% | Jan 17, 2026 | The Wallet System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2025-14075 | MEDIUM | 5.3 | 0.3% | Jan 17, 2026 | The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc... |
| CVE-2025-12718 | MEDIUM | 5.8 | 0.2% | Jan 17, 2026 | The Quick Contact Form plugin for WordPress is vulnerable to Open Mail Relay in all versions up to, and including, 8.2.6... |
| CVE-2025-12002 | MEDIUM | 5.9 | 0.4% | Jan 17, 2026 | The Feeds for YouTube Pro plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including... |
| CVE-2025-5489 | — | — | — | Jan 16, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-5102 | — | — | — | Jan 16, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-56451 | MEDIUM | 6.1 | 0.2% | Jan 16, 2026 | Cross site scripting vulnerability in seeyon Zhiyuan A8+ Collaborative Management Software 7.0 via the topValue paramete... |
| CVE-2025-15529 | HIGH | 7.5 | 0.7% | Jan 16, 2026 | A vulnerability was found in Open5GS up to 2.7.6. Affected by this issue is the function sgwc_s5c_handle_create_session_... |
| CVE-2025-15528 | HIGH | 7.5 | 0.8% | Jan 16, 2026 | A vulnerability has been found in Open5GS up to 2.7.6. Affected by this vulnerability is an unknown functionality of the... |
| CVE-2025-69581 | MEDIUM | 5.5 | 0.2% | Jan 16, 2026 | An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user i... |
| CVE-2025-68924 | HIGH | 7.5 | 0.7% | Jan 16, 2026 | In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a... |
| CVE-2025-62291 | HIGH | 8.1 | 0.9% | Jan 16, 2026 | In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted ... |
| CVE-2025-61873 | LOW | 2.6 | 0.2% | Jan 16, 2026 | Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV expor... |
| CVE-2025-48647 | HIGH | 7.8 | 0.1% | Jan 16, 2026 | In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc.c, there is a possible memory overwrite due to imprope... |
| CVE-2025-15032 | HIGH | 7.4 | 0.2% | Jan 16, 2026 | Missing about:blank indicator in custom-sized new windows in Dia before 1.9.0 on macOS could allow an attacker to spoof ... |
| CVE-2025-51602 | MEDIUM | 4.8 | 0.4% | Jan 16, 2026 | mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01... |
| CVE-2025-43904 | MEDIUM | 4.2 | 0.2% | Jan 16, 2026 | In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user ... |
| CVE-2025-43508 | MEDIUM | 5.5 | 0.1% | Jan 16, 2026 | A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able ... |
| CVE-2025-31510 | HIGH | 7.2 | 0.4% | Jan 16, 2026 | In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web... |
| CVE-2025-31186 | LOW | 3.3 | 0.1% | Jan 16, 2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to... |
| CVE-2025-24531 | MEDIUM | 6.7 | 0.2% | Jan 16, 2026 | In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as a... |
| CVE-2025-24528 | HIGH | 7.1 | 0.6% | Jan 16, 2026 | In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update... |
| CVE-2025-24090 | LOW | 3.3 | 0.1% | Jan 16, 2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app ... |
| CVE-2025-24089 | MEDIUM | 5.3 | 0.3% | Jan 16, 2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app ... |
| CVE-2025-71020 | HIGH | 7.5 | 0.3% | Jan 16, 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_4C408 function. T... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now