2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14149 | MEDIUM | 6.4 | 0.2% | Feb 27, 2026 | The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p... |
| CVE-2025-14040 | MEDIUM | 6.4 | 0.3% | Feb 27, 2026 | The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2025-56605 | MEDIUM | 5.4 | 0.2% | Feb 26, 2026 | A reflected Cross-Site Scripting (XSS) vulnerability exists in the register.php backend script of PuneethReddyHC Event M... |
| CVE-2025-64999 | MEDIUM | 5.4 | 0.1% | Feb 26, 2026 | Improper neutralization of input in Checkmk versions 2.4.0 before 2.4.0p22, and 2.3.0 before 2.3.0p43 allows an attacker... |
| CVE-2025-3525 | MEDIUM | 6.5 | 0.3% | Feb 25, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.7.5, 18.8 before 18.8.5, and 18... |
| CVE-2025-14103 | MEDIUM | 4.3 | 0.2% | Feb 25, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.7.5, 18.8 before 18.8.5, and 1... |
| CVE-2025-67601 | MEDIUM | 4.8 | 0.2% | Feb 25, 2026 | A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -ski... |
| CVE-2025-14742 | MEDIUM | 4.3 | 0.2% | Feb 25, 2026 | The WP Recipe Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check ... |
| CVE-2025-11563 | MEDIUM | 4.6 | 0.3% | Feb 25, 2026 | URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current ... |
| CVE-2025-5781 | MEDIUM | 5.2 | 0.1% | Feb 25, 2026 | Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitac... |
| CVE-2025-69231 | MEDIUM | 5.4 | 4.2% | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio... |
| CVE-2025-68277 | MEDIUM | 5 | 0.2% | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio... |
| CVE-2025-67491 | MEDIUM | 5.4 | 0.2% | Feb 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions 5.0.0.... |
| CVE-2025-46320 | MEDIUM | 6.1 | 0.2% | Feb 24, 2026 | A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access an... |
| CVE-2025-1787 | MEDIUM | 4.2 | 0.1% | Feb 24, 2026 | Local admin could to leak information from the Genetec Update Service configuration web page. An authenticated, admin pr... |
| CVE-2025-62512 | MEDIUM | 5.3 | 0.8% | Feb 24, 2026 | Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the ... |
| CVE-2025-47904 | MEDIUM | 4.1 | 0.1% | Feb 24, 2026 | Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software ... |
| CVE-2025-10010 | MEDIUM | 6.8 | 0.3% | Feb 24, 2026 | The CPSD CryptoPro Secure Disk application boots a small Linux operating system to perform user authentication before us... |
| CVE-2025-27555 | MEDIUM | 6.5 | 0.4% | Feb 24, 2026 | Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensiti... |
| CVE-2025-11848 | MEDIUM | 4.9 | 1.8% | Feb 24, 2026 | A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version throu... |
| CVE-2025-11847 | MEDIUM | 4.9 | 1.7% | Feb 24, 2026 | A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions thro... |
| CVE-2025-11846 | MEDIUM | 4.9 | 1.1% | Feb 24, 2026 | A null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions... |
| CVE-2025-11845 | MEDIUM | 4.9 | 0.8% | Feb 24, 2026 | A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware ve... |
| CVE-2025-69253 | MEDIUM | 5.3 | 0.3% | Feb 24, 2026 | free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of th... |
| CVE-2025-69251 | MEDIUM | 5.3 | 0.5% | Feb 24, 2026 | free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile co... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now