2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47337 | MEDIUM | 6.7 | 0.1% | Jan 7, 2026 | Memory corruption while accessing a synchronization object during concurrent operations. |
| CVE-2025-47336 | MEDIUM | 6.7 | 0.1% | Jan 7, 2026 | Memory corruption while performing sensor register read operations. |
| CVE-2025-47335 | MEDIUM | 6.7 | 0.1% | Jan 7, 2026 | Memory corruption while parsing clock configuration data for a specific hardware type. |
| CVE-2025-47334 | MEDIUM | 6.7 | 0.1% | Jan 7, 2026 | Memory corruption while processing shared command buffer packet between camera userspace and kernel. |
| CVE-2025-47333 | MEDIUM | 6.6 | 0.1% | Jan 7, 2026 | Memory corruption while handling buffer mapping operations in the cryptographic driver. |
| CVE-2025-47332 | MEDIUM | 6.4 | 0.1% | Jan 7, 2026 | Memory corruption while processing a config call from userspace. |
| CVE-2025-47331 | MEDIUM | 6.1 | 0.1% | Jan 7, 2026 | Information disclosure while processing a firmware event. |
| CVE-2025-47330 | MEDIUM | 5.5 | 0.1% | Jan 7, 2026 | Transient DOS while parsing video packets received from the video firmware. |
| CVE-2025-32300 | HIGH | 7.1 | 0.2% | Jan 7, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital zoom studi... |
| CVE-2025-31964 | MEDIUM | 4.9 | 0.4% | Jan 7, 2026 | Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged ... |
| CVE-2025-31963 | LOW | 3.3 | 0.1% | Jan 7, 2026 | Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2... |
| CVE-2025-31962 | MEDIUM | 4.3 | 0.2% | Jan 7, 2026 | Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authentic... |
| CVE-2025-31643 | HIGH | 8.8 | 0.3% | Jan 7, 2026 | Incorrect Privilege Assignment vulnerability in Dasinfomedia WPCHURCH allows Privilege Escalation.This issue affects WPC... |
| CVE-2025-15474 | MEDIUM | 5.3 | 0.3% | Jan 7, 2026 | AuntyFey Smart Combination Lock firmware versions as of 2025-12-24 contain a vulnerability that allows an unauthenticate... |
| CVE-2025-15472 | HIGH | 7.2 | 22.6% | Jan 7, 2026 | A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0. This affects the function setDeviceURL of the file uapply.cgi of ... |
| CVE-2025-15158 | HIGH | 8.8 | 0.5% | Jan 7, 2026 | The WP Enable WebP plugin for WordPress is vulnerable to arbitrary file uploads due to improper file type validation in ... |
| CVE-2025-15058 | MEDIUM | 6.4 | 0.3% | Jan 7, 2026 | The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'table_currency' ... |
| CVE-2025-15018 | CRITICAL | 9.8 | 0.3% | Jan 7, 2026 | The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to... |
| CVE-2025-15000 | MEDIUM | 4.4 | 0.2% | Jan 7, 2026 | The Page Keys plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘page_key’ parameter in all vers... |
| CVE-2025-14999 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The Latest Tabs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1... |
| CVE-2025-14904 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The Newsletter Email Subscribe plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i... |
| CVE-2025-14901 | MEDIUM | 6.5 | 0.4% | Jan 7, 2026 | The Bit Form – Contact Form Plugin plugin for WordPress is vulnerable to unauthorized workflow execution due to missing ... |
| CVE-2025-14891 | MEDIUM | 6.4 | 0.3% | Jan 7, 2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'displayN... |
| CVE-2025-14888 | MEDIUM | 4.4 | 0.2% | Jan 7, 2026 | The Simple User Meta Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user meta value fi... |
| CVE-2025-14887 | MEDIUM | 4.4 | 0.2% | Jan 7, 2026 | The twinklesmtp – Email Service Provider For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now