2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60262 | CRITICAL | 9.8 | 0.5% | Jan 6, 2026 | An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a mi... |
| CVE-2025-59379 | HIGH | 7.5 | 0.3% | Jan 6, 2026 | DwyerOmega Isensix Advanced Remote Monitoring System (ARMS) 1.5.7 allows an attacker to retrieve sensitive information f... |
| CVE-2025-14979 | HIGH | 7.8 | 0.1% | Jan 6, 2026 | AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privilege... |
| CVE-2025-46696 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application, version(s) versions 5.26 to 5.30, contain(s) an Executi... |
| CVE-2025-14026 | HIGH | 7.8 | 0.2% | Jan 6, 2026 | Forcepoint One DLP Client, version 23.04.5642 (and possibly newer versions), includes a restricted version of Python 2.5... |
| CVE-2025-9637 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized access ... |
| CVE-2025-9318 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injec... |
| CVE-2025-14552 | MEDIUM | 6.4 | 0.2% | Jan 6, 2026 | The MediaPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mpp-uploader shortcode... |
| CVE-2025-9294 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of... |
| CVE-2025-5919 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | The Appointment Booking and Scheduling Calendar Plugin – WP Timetics plugin for WordPress is vulnerable to unauthorized ... |
| CVE-2025-13964 | MEDIUM | 5.3 | 0.2% | Jan 6, 2026 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a m... |
| CVE-2025-13766 | MEDIUM | 5.4 | 0.1% | Jan 6, 2026 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthoriz... |
| CVE-2025-14371 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized m... |
| CVE-2025-13812 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ... |
| CVE-2025-12067 | MEDIUM | 6.4 | 0.2% | Jan 6, 2026 | The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table C... |
| CVE-2025-4776 | MEDIUM | 6.4 | 0.2% | Jan 6, 2026 | The Phlox theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption` HTML attribute in all ... |
| CVE-2025-13215 | MEDIUM | 5.3 | 0.2% | Jan 6, 2026 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all vers... |
| CVE-2025-15001 | CRITICAL | 9.8 | 0.3% | Jan 6, 2026 | The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all vers... |
| CVE-2025-14997 | HIGH | 8.8 | 0.6% | Jan 6, 2026 | The BuddyPress Xprofile Custom Field Types plugin for WordPress is vulnerable to arbitrary file deletion due to insuffic... |
| CVE-2025-14996 | CRITICAL | 9.8 | 0.3% | Jan 6, 2026 | The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via accoun... |
| CVE-2025-14441 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | The Popupkit plugin for WordPress is vulnerable to arbitrary subscriber data deletion due to missing authorization on th... |
| CVE-2025-14438 | MEDIUM | 6.4 | 0.2% | Jan 6, 2026 | The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, ... |
| CVE-2025-14120 | MEDIUM | 6.4 | 0.2% | Jan 6, 2026 | The URL Image Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver... |
| CVE-2025-14153 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | The Page Expire Popup/Redirection for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the '... |
| CVE-2025-14034 | MEDIUM | 5.3 | 0.2% | Jan 6, 2026 | The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of d... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now