2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31051 | MEDIUM | 5.3 | 0.2% | Jan 7, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EngoTheme Plant - Gardening ... |
| CVE-2025-15471 | CRITICAL | 9.8 | 12.1% | Jan 7, 2026 | A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goform... |
| CVE-2025-14612 | MEDIUM | 6.7 | 0.1% | Jan 7, 2026 | Insecure Temporary File vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows : Use of Predict... |
| CVE-2025-14605 | MEDIUM | 6.7 | 0.1% | Jan 7, 2026 | Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro on Windows (System Console modules) allows Se... |
| CVE-2025-14599 | MEDIUM | 6.7 | 0.1% | Jan 7, 2026 | Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard Installer (SFX) on Windows, Altera Qu... |
| CVE-2025-14596 | MEDIUM | 6.7 | 0.1% | Jan 7, 2026 | Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows Search ... |
| CVE-2025-30996 | CRITICAL | 9.9 | 0.4% | Jan 6, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themi... |
| CVE-2025-30631 | HIGH | 7.1 | 0.1% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team Woocommerc... |
| CVE-2025-29004 | HIGH | 8.8 | 0.3% | Jan 6, 2026 | Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Re... |
| CVE-2025-13744 | MEDIUM | 5.4 | 0.2% | Jan 6, 2026 | An Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server ... |
| CVE-2025-7048 | MEDIUM | 5.3 | 0.2% | Jan 6, 2026 | On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec proc... |
| CVE-2025-32304 | HIGH | 8.1 | 0.3% | Jan 6, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-15382 | HIGH | 8.1 | 0.3% | Jan 6, 2026 | A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote att... |
| CVE-2025-14942 | CRITICAL | 9.8 | 0.4% | Jan 6, 2026 | wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to ... |
| CVE-2025-69364 | MEDIUM | 5.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2025-69363 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in CyberChimps Responsive Addons for Elementor responsive-addons-for-elementor allow... |
| CVE-2025-69362 | MEDIUM | 5.9 | 0.1% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH UiChemy u... |
| CVE-2025-69361 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in PublishPress Post Expirator post-expirator allows Exploiting Incorrectly Configur... |
| CVE-2025-69360 | MEDIUM | 6.5 | 0.1% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem... |
| CVE-2025-69359 | MEDIUM | 5.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in WPFunnels Creator LMS creatorlms allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-69357 | MEDIUM | 6.5 | 0.1% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem... |
| CVE-2025-69356 | HIGH | 7.5 | 0.3% | Jan 6, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-69355 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in Tickera Tickera tickera-event-ticketing-system allows Exploiting Incorrectly Conf... |
| CVE-2025-69354 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in BBR Plugins Better Business Reviews better-business-reviews allows Exploiting Inc... |
| CVE-2025-69353 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in Proxy & VPN Blocker Proxy & VPN Blocker proxy-vpn-blocker allows Exploiting Incor... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now