2025 CVE Vulnerabilities
45,124 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15544 | MEDIUM | 5.9 | 0.1% | Aug 3, 2026 | A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials assoc... |
| CVE-2025-9291 | MEDIUM | 6.5 | 0.2% | Aug 3, 2026 | A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certif... |
| CVE-2025-15673 | MEDIUM | 4.9 | 0.2% | Aug 3, 2026 | The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads an... |
| CVE-2025-15675 | MEDIUM | 4.8 | 0.2% | Aug 2, 2026 | The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields befor... |
| CVE-2025-71404 | MEDIUM | 5.1 | 0.4% | Aug 1, 2026 | better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the ... |
| CVE-2025-14073 | MEDIUM | 5.3 | 0.2% | Aug 1, 2026 | The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecur... |
| CVE-2025-14469 | MEDIUM | 4.3 | 0.1% | Aug 1, 2026 | The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2025-15669 | MEDIUM | 4.8 | 0.2% | Aug 1, 2026 | The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before ren... |
| CVE-2025-62347 | MEDIUM | 4.3 | — | Jul 31, 2026 | HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and... |
| CVE-2025-67651 | MEDIUM | 6.9 | — | Jul 31, 2026 | A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF ... |
| CVE-2025-65342 | MEDIUM | 6.1 | 0.1% | Jul 30, 2026 | code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field. |
| CVE-2025-65341 | MEDIUM | 6.1 | 0.1% | Jul 30, 2026 | Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php. |
| CVE-2025-51684 | MEDIUM | 6.1 | 0.2% | Jul 30, 2026 | CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data ... |
| CVE-2025-36374 | MEDIUM | 5.5 | — | Jul 30, 2026 | IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privile... |
| CVE-2025-0152 | MEDIUM | 6.1 | — | Jul 30, 2026 | IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1... |
| CVE-2025-36431 | MEDIUM | 5.4 | — | Jul 30, 2026 | IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnera... |
| CVE-2025-36298 | MEDIUM | 5.4 | 0.2% | Jul 30, 2026 | IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0... |
| CVE-2025-65337 | MEDIUM | 6.1 | 0.1% | Jul 29, 2026 | Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.php via the address ... |
| CVE-2025-59181 | MEDIUM | 4.8 | 0.3% | Jul 27, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuratio... |
| CVE-2025-59180 | MEDIUM | 5.1 | 0.1% | Jul 27, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm s... |
| CVE-2025-59178 | MEDIUM | 4.8 | 0.1% | Jul 27, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnera... |
| CVE-2025-59177 | MEDIUM | 6.8 | 0.1% | Jul 27, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowi... |
| CVE-2025-9205 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.... |
| CVE-2025-68081 | MEDIUM | 5.9 | — | Jul 23, 2026 | Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions. |
| CVE-2025-50325 | MEDIUM | 5.4 | 0.3% | Jul 22, 2026 | BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypa... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now