2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13456 | MEDIUM | 6.1 | 0.2% | Jan 2, 2026 | The ShopBuilder WordPress plugin before 3.2.2 does not sanitise and escape a parameter before outputting it back in the... |
| CVE-2025-13153 | MEDIUM | 6.1 | 0.2% | Jan 2, 2026 | The Logo Slider WordPress plugin before 4.9.0 does not validate and escape some of its slider options before outputting... |
| CVE-2025-12685 | MEDIUM | 6.5 | 0.1% | Jan 2, 2026 | The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthentica... |
| CVE-2025-15428 | HIGH | 8.8 | 0.8% | Jan 2, 2026 | A weakness has been identified in UTT 进取 512W 1.7.7-171114. Affected is the function strcpy of the file /goform/formRemo... |
| CVE-2025-15427 | — | — | — | Jan 2, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn b... |
| CVE-2025-15426 | HIGH | 7.3 | 0.4% | Jan 2, 2026 | A vulnerability was identified in jackying H-ui.admin up to 3.1. This affects an unknown function in the library /lib/we... |
| CVE-2025-15425 | CRITICAL | 9.8 | 0.5% | Jan 2, 2026 | A vulnerability was determined in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/de... |
| CVE-2025-15424 | CRITICAL | 9.8 | 0.4% | Jan 2, 2026 | A vulnerability was found in Yonyou KSOA 9.0. The affected element is an unknown function of the file /worksheet/agent_w... |
| CVE-2025-15423 | HIGH | 8.8 | 0.3% | Jan 2, 2026 | A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the ... |
| CVE-2025-14998 | CRITICAL | 9.8 | 0.5% | Jan 2, 2026 | The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and in... |
| CVE-2025-14047 | MEDIUM | 5.3 | 0.2% | Jan 2, 2026 | The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User ... |
| CVE-2025-15422 | HIGH | 7.5 | 1.1% | Jan 2, 2026 | A flaw has been found in EmpireSoft EmpireCMS up to 8.0. This issue affects the function egetip of the file e/class/conn... |
| CVE-2025-15421 | CRITICAL | 9.8 | 0.4% | Jan 2, 2026 | A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/agent_wo... |
| CVE-2025-15420 | CRITICAL | 9.8 | 0.4% | Jan 2, 2026 | A security vulnerability has been detected in Yonyou KSOA 9.0. This affects an unknown part of the file /worksheet/agent... |
| CVE-2025-15419 | MEDIUM | 5.5 | 0.2% | Jan 2, 2026 | A weakness has been identified in Open5GS up to 2.7.6. Affected by this issue is the function sgwc_s5c_handle_create_ses... |
| CVE-2025-15418 | MEDIUM | 5.5 | 0.2% | Jan 2, 2026 | A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function ogs_gtp2_pars... |
| CVE-2025-15417 | MEDIUM | 5.5 | 0.2% | Jan 1, 2026 | A vulnerability was identified in Open5GS up to 2.7.6. Affected is the function sgwc_s11_handle_create_session_request o... |
| CVE-2025-15416 | MEDIUM | 5.4 | 0.2% | Jan 1, 2026 | A vulnerability was found in xnx3 wangmarket up to 6.4. This affects an unknown function of the file /siteVar/save.do of... |
| CVE-2025-15415 | MEDIUM | 5.4 | 0.2% | Jan 1, 2026 | A vulnerability has been found in xnx3 wangmarket up to 6.4. The impacted element is the function uploadImage of the fil... |
| CVE-2025-15414 | MEDIUM | 4.7 | 0.2% | Jan 1, 2026 | A flaw has been found in go-sonic sonic up to 1.1.4. The affected element is the function FetchTheme of the file service... |
| CVE-2025-15413 | HIGH | 7.8 | 0.2% | Jan 1, 2026 | A vulnerability was detected in wasm3 up to 0.5.0. Impacted is the function op_SetSlot_i32/op_CallIndirect of the file m... |
| CVE-2025-15412 | HIGH | 7.8 | 0.2% | Jan 1, 2026 | A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decom... |
| CVE-2025-15411 | HIGH | 7.8 | 0.2% | Jan 1, 2026 | A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::Inse... |
| CVE-2025-69203 | HIGH | 8.8 | 0.3% | Jan 1, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the access req... |
| CVE-2025-68620 | CRITICAL | 9.1 | 0.5% | Jan 1, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two featur... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now