2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15441 | MEDIUM | 6.8 | 0.3% | Apr 13, 2026 | The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" ... |
| CVE-2025-66447 | MEDIUM | 4.7 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. From 1.11.0 to 2.0-beta.1, anyone can trigger a malicious redirect through ... |
| CVE-2025-14545 | MEDIUM | 6.5 | 0.3% | Apr 10, 2026 | The YML for Yandex Market WordPress plugin before 5.0.26 is vulnerable to Remote Code Execution via the feed generation ... |
| CVE-2025-70797 | MEDIUM | 6.1 | 0.3% | Apr 9, 2026 | Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via... |
| CVE-2025-63238 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | A Reflected Cross-Site Scripting (XSS) affects LimeSurvey versions prior to 6.15.11+250909, due to the lack of validatio... |
| CVE-2025-70365 | MEDIUM | 5.4 | 0.1% | Apr 9, 2026 | A stored cross-site scripting (XSS) vulnerability exists in Kiamo before 8.4 due to improper output encoding of user-sup... |
| CVE-2025-70811 | MEDIUM | 4.3 | 0.1% | Apr 9, 2026 | Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via t... |
| CVE-2025-45806 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | A cross-site scripting (XSS) vulnerability in rrweb-snapshot before v2.0.0-alpha.18 allows attackers to execute arbitrar... |
| CVE-2025-9484 | MEDIUM | 4.3 | 0.3% | Apr 8, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 16.6 before 18.8.9, 18.9 before 18.9.5, and 18.1... |
| CVE-2025-57175 | MEDIUM | 6.8 | 0.1% | Apr 8, 2026 | Siklu EtherHaul 8010 siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b devices have a static root password. |
| CVE-2025-14243 | MEDIUM | 5.3 | 0.3% | Apr 8, 2026 | A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enum... |
| CVE-2025-58713 | MEDIUM | 6.4 | 0.1% | Apr 8, 2026 | A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems f... |
| CVE-2025-57854 | MEDIUM | 6.4 | 0.1% | Apr 8, 2026 | A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from... |
| CVE-2025-57853 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd fi... |
| CVE-2025-57851 | MEDIUM | 6.7 | 0.1% | Apr 8, 2026 | A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems f... |
| CVE-2025-57847 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from th... |
| CVE-2025-1794 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded SVG files in all vers... |
| CVE-2025-14732 | MEDIUM | 6.4 | 0.3% | Apr 8, 2026 | The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2025-20628 | MEDIUM | 6.9 | 0.2% | Apr 7, 2026 | An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) w... |
| CVE-2025-14858 | MEDIUM | 5.1 | 0.1% | Apr 7, 2026 | The Semtech LR11xx LoRa transceivers running early versions of firmware contains an information disclosure vulnerability... |
| CVE-2025-14857 | MEDIUM | 5.4 | 0.2% | Apr 7, 2026 | An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware ... |
| CVE-2025-70844 | MEDIUM | 6.1 | 0.3% | Apr 7, 2026 | yaffa v2.0.0 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript into the "Add Acco... |
| CVE-2025-14944 | MEDIUM | 5.3 | 0.6% | Apr 7, 2026 | The Backup Migration plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2... |
| CVE-2025-24819 | MEDIUM | 5.7 | 0.2% | Apr 7, 2026 | Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter... |
| CVE-2025-15611 | MEDIUM | 5.4 | 0.1% | Apr 7, 2026 | The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function be... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now