2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15506 | LOW | 3.3 | 0.2% | Jan 11, 2026 | A vulnerability was found in AcademySoftwareFoundation OpenColorIO up to 2.5.0. This issue affects the function ConvertT... |
| CVE-2025-15505 | LOW | 2.4 | 0.2% | Jan 11, 2026 | A vulnerability was found in Luxul XWR-600 up to 4.0.1. The affected element is an unknown function of the component Web... |
| CVE-2025-13393 | MEDIUM | 4.3 | 0.2% | Jan 10, 2026 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up ... |
| CVE-2025-12379 | MEDIUM | 6.4 | 0.2% | Jan 10, 2026 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2025-14555 | MEDIUM | 6.4 | 0.2% | Jan 10, 2026 | The Countdown Timer – Widget Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'... |
| CVE-2025-15504 | MEDIUM | 5.5 | 0.2% | Jan 10, 2026 | A security flaw has been discovered in lief-project LIEF up to 0.17.1. Affected by this issue is the function Parser::pa... |
| CVE-2025-14506 | MEDIUM | 6.4 | 0.2% | Jan 10, 2026 | The ConvertForce Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gutenberg block... |
| CVE-2025-62235 | HIGH | 8.1 | 0.4% | Jan 10, 2026 | Authentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could le... |
| CVE-2025-53477 | HIGH | 7.5 | 0.7% | Jan 10, 2026 | NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command T... |
| CVE-2025-53470 | LOW | 3.1 | 0.3% | Jan 10, 2026 | Out-of-bounds Read vulnerability in Apache NimBLE HCI H4 driver. Specially crafted HCI event could lead to invalid memo... |
| CVE-2025-52435 | HIGH | 7.5 | 0.2% | Jan 10, 2026 | J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause ... |
| CVE-2025-15503 | CRITICAL | 9.8 | 1.9% | Jan 10, 2026 | A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted ele... |
| CVE-2025-14976 | MEDIUM | 5.4 | 0.1% | Jan 10, 2026 | The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restrict... |
| CVE-2025-15502 | CRITICAL | 9.8 | 5.6% | Jan 10, 2026 | A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element ... |
| CVE-2025-14948 | MEDIUM | 5.3 | 0.2% | Jan 10, 2026 | The miniOrange OTP Verification and SMS Notification for WooCommerce plugin for WordPress is vulnerable to unauthorized ... |
| CVE-2025-14943 | MEDIUM | 4.3 | 0.2% | Jan 10, 2026 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure... |
| CVE-2025-65091 | CRITICAL | 10 | 0.3% | Jan 10, 2026 | XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right t... |
| CVE-2025-65090 | MEDIUM | 5.3 | 0.2% | Jan 10, 2026 | XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights ... |
| CVE-2025-61676 | MEDIUM | 4.8 | 0.2% | Jan 10, 2026 | October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripti... |
| CVE-2025-61674 | MEDIUM | 4.8 | 0.2% | Jan 10, 2026 | October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripti... |
| CVE-2025-13457 | HIGH | 7.5 | 0.3% | Jan 10, 2026 | The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and... |
| CVE-2025-68470 | MEDIUM | 6.5 | 0.2% | Jan 10, 2026 | React Router is a router for React. In versions 6.0.0 through 6.30.1 and 7.0.0 through 7.9.5, an attacker-supplied path ... |
| CVE-2025-61686 | CRITICAL | 9.1 | 16.1% | Jan 10, 2026 | React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version... |
| CVE-2025-59057 | HIGH | 7.6 | 0.4% | Jan 10, 2026 | React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 ... |
| CVE-2025-15501 | CRITICAL | 9.8 | 6.4% | Jan 9, 2026 | A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the funct... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now