2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67547 | MEDIUM | 6.5 | 0.3% | Feb 20, 2026 | Missing Authorization vulnerability in uixthemes Konte konte allows Exploiting Incorrectly Configured Access Control Sec... |
| CVE-2025-67438 | MEDIUM | 6.1 | 0.3% | Feb 20, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability in Sync-in Server before 1.9.3 allows an authenticated attacker to exe... |
| CVE-2025-60183 | MEDIUM | 5.9 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in silence Silencesof... |
| CVE-2025-59819 | MEDIUM | 6.5 | 0.4% | Feb 20, 2026 | This vulnerability allows authenticated attackers to read an arbitrary file by changing a filepath parameter into an int... |
| CVE-2025-9208 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ W... |
| CVE-2025-8055 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Server-Side Request Forgery (SSRF) vulnerability in OpenText™ XM Fax allows Server Side Request Forgery. The vulnerabi... |
| CVE-2025-13672 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ W... |
| CVE-2025-13671 | MEDIUM | 6.5 | 0.1% | Feb 19, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in OpenText™ Web Site Management Server allows Cross Site Request Forger... |
| CVE-2025-69725 | MEDIUM | 4.7 | 0.2% | Feb 19, 2026 | An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect vi... |
| CVE-2025-69674 | MEDIUM | 6.4 | 0.2% | Feb 19, 2026 | Buffer Overflow vulnerability in CDATA FD614GS3-R850 V3.2.7_P161006 (Build.0333.250211) allows an attacker to execute ar... |
| CVE-2025-71244 | MEDIUM | 6.1 | 0.2% | Feb 19, 2026 | SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a m... |
| CVE-2025-71242 | MEDIUM | 6.5 | 0.2% | Feb 19, 2026 | SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does n... |
| CVE-2025-71241 | MEDIUM | 6.1 | 0.2% | Feb 19, 2026 | SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the private area. The content of the error me... |
| CVE-2025-71240 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | SPIP before 4.2.15 allows Cross-Site Scripting (XSS) via crafted content in HTML code tags. The application does not pro... |
| CVE-2025-15563 | MEDIUM | 5.3 | 0.3% | Feb 19, 2026 | Any unauthenticated user can reset the WorkTime on-prem database configuration by sending a specific HTTP request to the... |
| CVE-2025-15562 | MEDIUM | 6.1 | 0.2% | Feb 19, 2026 | The server API endpoint /report/internet/urls reflects received data into the HTML response without applying proper enco... |
| CVE-2025-41023 | MEDIUM | 6.9 | 0.4% | Feb 19, 2026 | An authentication bypass vulnerability has been found in Thesamur's AutoGPT. This vulnerability allows an attacker to by... |
| CVE-2025-40697 | MEDIUM | 5.1 | 0.4% | Feb 19, 2026 | Reflected Cross-Site Scripting (XSS) vulnerability in '/index.php' in Lewe WebMeasure, which allows remote attackers to ... |
| CVE-2025-14983 | MEDIUM | 6.4 | 0.3% | Feb 19, 2026 | The Advanced Custom Fields: Font Awesome Field plugin for WordPress is vulnerable to Cross-Site Scripting in all version... |
| CVE-2025-14864 | MEDIUM | 4.3 | 0.3% | Feb 19, 2026 | The Virusdie - One-click website security plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve... |
| CVE-2025-14851 | MEDIUM | 6.4 | 0.2% | Feb 19, 2026 | The YaMaps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `yamap` shortcode par... |
| CVE-2025-14445 | MEDIUM | 6.4 | 0.2% | Feb 19, 2026 | The Image Hotspot by DevVN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hotspot_content' c... |
| CVE-2025-14427 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | The Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to u... |
| CVE-2025-14357 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | The Mega Store Woocommerce theme for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2025-14342 | MEDIUM | 4.3 | 0.3% | Feb 19, 2026 | The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now