2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0180 | CRITICAL | 9.8 | 0.5% | Feb 11, 2025 | The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7. ... |
| CVE-2025-1177 | CRITICAL | 9.8 | 0.7% | Feb 11, 2025 | A vulnerability was found in dayrui XunRuiCMS 4.6.3. It has been classified as critical. Affected is the function import... |
| CVE-2025-1144 | CRITICAL | 9.8 | 0.5% | Feb 11, 2025 | School Affairs System from Quanxun has an Exposure of Sensitive Information, allowing unauthenticated attackers to view ... |
| CVE-2025-1168 | CRITICAL | 9.8 | 0.5% | Feb 11, 2025 | A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been declared as critical. Th... |
| CVE-2025-1167 | CRITICAL | 9.8 | 0.5% | Feb 11, 2025 | A vulnerability was found in Mayuri K Employee Management System up to 192.168.70.3 and classified as critical. Affected... |
| CVE-2025-1160 | CRITICAL | 9.8 | 0.8% | Feb 10, 2025 | A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by t... |
| CVE-2025-24016 | CRITICAL | 9.9 | 92.6% | Feb 10, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 ... |
| CVE-2025-24032 | CRITICAL | 9.2 | 0.7% | Feb 10, 2025 | PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. Prior to version 0.6.13, if ce... |
| CVE-2025-0316 | CRITICAL | 9.8 | 0.7% | Feb 8, 2025 | The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including... |
| CVE-2025-24028 | CRITICAL | 9.6 | 0.5% | Feb 7, 2025 | Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into... |
| CVE-2025-1113 | CRITICAL | 9.8 | 0.5% | Feb 7, 2025 | A vulnerability was found in taisan tarzan-cms up to 1.0.0. It has been rated as critical. This issue affects the functi... |
| CVE-2025-1104 | CRITICAL | 9.8 | 2.7% | Feb 7, 2025 | A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical. This vulnerability affects unknown ... |
| CVE-2025-1107 | CRITICAL | 9.9 | 0.4% | Feb 7, 2025 | Unverified password change vulnerability in Janto, versions prior to r12. This could allow an unauthenticated attacker t... |
| CVE-2025-25167 | CRITICAL | 9.8 | 0.4% | Feb 7, 2025 | Missing Authorization vulnerability in Black and White BookPress – For Book Authors book-press allows Exploiting Incorre... |
| CVE-2025-25163 | CRITICAL | 9.8 | 1.9% | Feb 7, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Zach Swetz Plugin A/B Im... |
| CVE-2025-25107 | CRITICAL | 9.6 | 0.2% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in sainwp OneStore Sites onestore-sites allows Cross Site Request Forger... |
| CVE-2025-25106 | CRITICAL | 9.6 | 0.2% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in FancyWP Starter Templates by FancyWP starter-templates allows Cross S... |
| CVE-2025-25101 | CRITICAL | 9.6 | 0.5% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in MetricThemes Munk Sites munk-sites allows Cross Site Request Forgery.... |
| CVE-2025-1077 | CRITICAL | 9.5 | 0.8% | Feb 7, 2025 | A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS,... |
| CVE-2025-1061 | CRITICAL | 9.8 | 0.6% | Feb 7, 2025 | The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin... |
| CVE-2025-0674 | CRITICAL | 9.8 | 3.8% | Feb 7, 2025 | Multiple Elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the ... |
| CVE-2025-24786 | CRITICAL | 9.1 | 2.7% | Feb 6, 2025 | WhoDB is an open source database management tool. While the application only displays Sqlite3 databases present in the d... |
| CVE-2025-22992 | CRITICAL | 9.8 | 0.5% | Feb 6, 2025 | A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerabili... |
| CVE-2025-24981 | CRITICAL | 9.3 | 0.6% | Feb 6, 2025 | MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. In affected versions... |
| CVE-2025-0982 | CRITICAL | 10 | 0.2% | Feb 6, 2025 | Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an actor to execute arbitra... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now