2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13854 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The Curved Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'radius' parameter of the arct... |
| CVE-2025-13852 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The Debt.com Business in a Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configuration'... |
| CVE-2025-13717 | MEDIUM | 5.3 | 0.3% | Jan 9, 2026 | The Contact Form vCard Generator plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa... |
| CVE-2025-13704 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The Autogen Headers Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'head_class' paramete... |
| CVE-2025-13701 | MEDIUM | 6.1 | 0.3% | Jan 9, 2026 | The Shabat Keeper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] para... |
| CVE-2025-11453 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The Header and Footer Scripts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _inpost_head_scr... |
| CVE-2025-9222 | MEDIUM | 5.4 | 0.4% | Jan 9, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and... |
| CVE-2025-64093 | CRITICAL | 9.8 | 0.7% | Jan 9, 2026 | Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname... |
| CVE-2025-64092 | HIGH | 7.5 | 0.4% | Jan 9, 2026 | This vulnerability allows unauthenticated attackers to inject an SQL request into GET request parameters and directly qu... |
| CVE-2025-64091 | HIGH | 8.8 | 0.3% | Jan 9, 2026 | This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device. |
| CVE-2025-64090 | HIGH | 8.8 | 0.4% | Jan 9, 2026 | This vulnerability allows authenticated attackers to execute commands via the hostname of the device. |
| CVE-2025-3950 | LOW | 3.5 | 0.2% | Jan 9, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 1... |
| CVE-2025-13900 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The WP Popup Magic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the [wp... |
| CVE-2025-13895 | MEDIUM | 6.1 | 0.2% | Jan 9, 2026 | The Top Position Google Finance plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['... |
| CVE-2025-13853 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The Nearby Now Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_tech' parameter o... |
| CVE-2025-13781 | MEDIUM | 6.5 | 0.4% | Jan 9, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.5.5, 18.6 before 18.6.3, and 18.7... |
| CVE-2025-13772 | MEDIUM | 4.3 | 0.4% | Jan 9, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7... |
| CVE-2025-13761 | CRITICAL | 9.6 | 0.6% | Jan 9, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 th... |
| CVE-2025-13729 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The Entry Views plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'entry-views' shortco... |
| CVE-2025-11246 | MEDIUM | 5.4 | 0.4% | Jan 9, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.4 before 18.5.5, 18.6 before 18.6.3, and 1... |
| CVE-2025-10569 | MEDIUM | 6.5 | 0.5% | Jan 9, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.5.5, 18.6 before 18.6.3, and 18... |
| CVE-2025-69195 | HIGH | 8.8 | 0.3% | Jan 9, 2026 | A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization lo... |
| CVE-2025-69194 | CRITICAL | 9.8 | 0.7% | Jan 9, 2026 | A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validat... |
| CVE-2025-14937 | HIGH | 7.2 | 0.3% | Jan 9, 2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acff' parame... |
| CVE-2025-14741 | CRITICAL | 9.1 | 0.4% | Jan 9, 2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modifi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now