2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15030 | CRITICAL | 9.8 | 0.5% | Feb 2, 2026 | The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few u... |
| CVE-2025-24293 | CRITICAL | 9.2 | 2.4% | Jan 30, 2026 | # Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of pote... |
| CVE-2025-51958 | CRITICAL | 9.8 | 0.6% | Jan 30, 2026 | aelsantex runcommand 2014-04-01, a plugin for DokuWiki, allows unauthenticated attackers to execute arbitrary system com... |
| CVE-2025-7964 | CRITICAL | 9.2 | 0.3% | Jan 30, 2026 | After receiving a malformed 802.15.4 MAC Data Request the Zigbee Coordinator sends a ‘network leave’ request to Zigb... |
| CVE-2025-26385 | CRITICAL | 9.5 | 1.4% | Jan 30, 2026 | Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Com... |
| CVE-2025-69929 | CRITICAL | 9.8 | 0.4% | Jan 29, 2026 | An issue in N3uron Web User Interface v.1.21.7-240207.1047 allows a remote attacker to escalate privileges via the passw... |
| CVE-2025-7714 | CRITICAL | 9.8 | 0.3% | Jan 29, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Global Interactive... |
| CVE-2025-7013 | CRITICAL | 9.8 | 0.3% | Jan 29, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Explo... |
| CVE-2025-7016 | CRITICAL | 9.8 | 0.3% | Jan 29, 2026 | Improper Access Control vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Aut... |
| CVE-2025-7015 | CRITICAL | 9.8 | 0.2% | Jan 29, 2026 | Session Fixation vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Session Fi... |
| CVE-2025-68662 | CRITICAL | 9.9 | 0.3% | Jan 28, 2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostn... |
| CVE-2025-69602 | CRITICAL | 9.1 | 0.3% | Jan 28, 2026 | A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate th... |
| CVE-2025-57795 | CRITICAL | 9.9 | 0.5% | Jan 28, 2026 | Explorance Blue versions prior to 8.14.13 contain an authenticated remote file download vulnerability in a web service c... |
| CVE-2025-57794 | CRITICAL | 9.1 | 0.5% | Jan 28, 2026 | Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administ... |
| CVE-2025-57792 | CRITICAL | 10 | 0.4% | Jan 28, 2026 | Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user... |
| CVE-2025-61140 | CRITICAL | 9.8 | 0.4% | Jan 28, 2026 | The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution. |
| CVE-2025-40554 | CRITICAL | 9.8 | 58.4% | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could... |
| CVE-2025-40553 | CRITICAL | 9.8 | 60.4% | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead ... |
| CVE-2025-40552 | CRITICAL | 9.8 | 49.7% | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would ... |
| CVE-2025-40551 | CRITICAL | 9.8 | 84.1% | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead ... |
| CVE-2025-40536 | CRITICAL | 9.8 | 81.6% | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could... |
| CVE-2025-21589 | CRITICAL | 9.8 | 1.4% | Jan 27, 2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may a... |
| CVE-2025-14988 | CRITICAL | 10 | 0.4% | Jan 27, 2026 | A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain co... |
| CVE-2025-69564 | CRITICAL | 9.8 | 0.4% | Jan 27, 2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Addres... |
| CVE-2025-69563 | CRITICAL | 9.8 | 0.4% | Jan 27, 2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password paramete... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now