2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12081 | MEDIUM | 4.3 | 0.3% | Feb 19, 2026 | The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap... |
| CVE-2025-12027 | MEDIUM | 4.3 | 0.3% | Feb 19, 2026 | The Mesmerize Companion plugin for WordPress is vulnerable to unauthorized access and modification of data due to a miss... |
| CVE-2025-11725 | MEDIUM | 6.5 | 0.3% | Feb 19, 2026 | The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil... |
| CVE-2025-11706 | MEDIUM | 6.1 | 0.3% | Feb 19, 2026 | The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the dbstatus parameter ... |
| CVE-2025-15585 | MEDIUM | 6.7 | 0.2% | Feb 19, 2026 | Fileflows versions before 25.05.2 are affected by an authenticated SQL injection vulnerability in the library-file searc... |
| CVE-2025-15581 | MEDIUM | 4.7 | 0.4% | Feb 18, 2026 | Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authenticati... |
| CVE-2025-12812 | MEDIUM | 5.3 | 0.3% | Feb 18, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Delinea Inc. Cloud Suite and Pri... |
| CVE-2025-12811 | MEDIUM | 6.9 | 0.3% | Feb 18, 2026 | Improper Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Delinea Inc. Cloud Suite and Privile... |
| CVE-2025-14876 | MEDIUM | 5.5 | 0.1% | Feb 18, 2026 | A flaw was found in the virtio-crypto device of QEMU. A malicious guest operating system can exploit a missing length li... |
| CVE-2025-12343 | MEDIUM | 5.5 | 0.1% | Feb 18, 2026 | A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in... |
| CVE-2025-10256 | MEDIUM | 5.5 | 0.3% | Feb 18, 2026 | A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a... |
| CVE-2025-0577 | MEDIUM | 4.8 | 0.2% | Feb 18, 2026 | An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return pr... |
| CVE-2025-70063 | MEDIUM | 6.5 | 0.3% | Feb 18, 2026 | The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference ... |
| CVE-2025-70062 | MEDIUM | 6.5 | 0.2% | Feb 18, 2026 | PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor... |
| CVE-2025-69287 | MEDIUM | 5.4 | 0.3% | Feb 18, 2026 | The BSV Blockchain SDK is a unified TypeScript SDK for developing scalable apps on the BSV Blockchain. Prior to version ... |
| CVE-2025-71237 | MEDIUM | 5.5 | 0.1% | Feb 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: nilfs2: Fix potential block overflow that cause sys... |
| CVE-2025-71236 | MEDIUM | 5.5 | 0.1% | Feb 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Validate sp before freeing associate... |
| CVE-2025-71235 | MEDIUM | 5.5 | 0.1% | Feb 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Delay module unload while fabric sca... |
| CVE-2025-71233 | MEDIUM | 5.5 | 0.1% | Feb 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Avoid creating sub-groups asynchrono... |
| CVE-2025-71232 | MEDIUM | 5.5 | 0.1% | Feb 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Free sp in error path to fix system ... |
| CVE-2025-71230 | MEDIUM | 5.5 | 0.1% | Feb 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: hfs: ensure sb->s_fs_info is always cleaned up Whe... |
| CVE-2025-71229 | MEDIUM | 5.5 | 0.1% | Feb 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Fix alignment fault in rtw_core_enable... |
| CVE-2025-65519 | MEDIUM | 6.5 | 0.3% | Feb 18, 2026 | mayswind ezbookkeeping versions 1.2.0 and earlier contain a critical vulnerability in JSON and XML file import processin... |
| CVE-2025-71227 | MEDIUM | 5.5 | 0.1% | Feb 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: don't WARN for connections on inval... |
| CVE-2025-71225 | MEDIUM | 5.3 | 0.1% | Feb 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: md: suspend array while updating raid_disks via sys... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now