2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14982 | MEDIUM | 4.3 | 0.3% | Jan 16, 2026 | The Booking Calendar plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Exposu... |
| CVE-2025-14384 | MEDIUM | 4.3 | 0.2% | Jan 16, 2026 | The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to ... |
| CVE-2025-12957 | HIGH | 8.8 | 0.6% | Jan 16, 2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and incl... |
| CVE-2025-12641 | MEDIUM | 6.5 | 0.4% | Jan 16, 2026 | The Awesome Support - WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to mis... |
| CVE-2025-62582 | CRITICAL | 9.8 | 0.5% | Jan 16, 2026 | Delta Electronics DIAView has multiple vulnerabilities. |
| CVE-2025-62581 | CRITICAL | 9.8 | 0.5% | Jan 16, 2026 | Delta Electronics DIAView has multiple vulnerabilities. |
| CVE-2025-65118 | CRITICAL | 9.3 | 0.3% | Jan 16, 2026 | The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimizatio... |
| CVE-2025-65117 | HIGH | 7.7 | 0.2% | Jan 16, 2026 | The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed O... |
| CVE-2025-64769 | HIGH | 7.6 | 0.2% | Jan 16, 2026 | The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted an... |
| CVE-2025-64729 | HIGH | 8.2 | 0.2% | Jan 16, 2026 | The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optim... |
| CVE-2025-64691 | CRITICAL | 9.3 | 0.3% | Jan 16, 2026 | The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scr... |
| CVE-2025-61943 | HIGH | 7.8 | 0.3% | Jan 16, 2026 | The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper ... |
| CVE-2025-61937 | CRITICAL | 10 | 1.5% | Jan 16, 2026 | The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS sys... |
| CVE-2025-14237 | CRITICAL | 9.8 | 0.9% | Jan 16, 2026 | Buffer overflow in XPS font parse processing on Small Office Multifunction Printers and Laser Printers(*) which may allo... |
| CVE-2025-14236 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Buffer overflow in Address Book attribute tag processing on Small Office Multifunction Printers(*) which may allow an at... |
| CVE-2025-14235 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Buffer overflow in XPS font fpgm data processing on Small Office Multifunction Printers and Laser Printers(*) which may ... |
| CVE-2025-14234 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Buffer overflow in CPCA list processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an ... |
| CVE-2025-14233 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may all... |
| CVE-2025-14232 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Buffer overflow in XML processing of XPS file in Small Office Multifunction Printers and Laser Printers(*) which may all... |
| CVE-2025-14231 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Buffer overflow in print job processing by WSD on Small Office Multifunction Printers and Laser Printers(*) which may al... |
| CVE-2025-68671 | MEDIUM | 4.8 | 0.2% | Jan 15, 2026 | lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not ... |
| CVE-2025-67823 | HIGH | 8.2 | 0.3% | Jan 15, 2026 | A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX thro... |
| CVE-2025-67822 | CRITICAL | 9.4 | 0.4% | Jan 15, 2026 | A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.... |
| CVE-2025-70893 | HIGH | 8.8 | 0.4% | Jan 15, 2026 | A time-based blind SQL Injection vulnerability exists in PHPGurukul Cyber Cafe Management System v1.0 within the adminpr... |
| CVE-2025-70892 | CRITICAL | 9.8 | 0.4% | Jan 15, 2026 | Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now