2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8308 | MEDIUM | 6.3 | 0.2% | Feb 18, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Key Softwar... |
| CVE-2025-8781 | MEDIUM | 4.9 | 0.3% | Feb 18, 2026 | The Bookster – WordPress Appointment Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘raw’ pa... |
| CVE-2025-7630 | MEDIUM | 5.3 | 0.2% | Feb 18, 2026 | Improper Restriction of Excessive Authentication Attempts, Improper Authentication vulnerability in Doruk Communication ... |
| CVE-2025-14799 | MEDIUM | 6.5 | 0.5% | Feb 18, 2026 | The Brevo - Email, SMS, Web Push, Chat, and more. plugin for WordPress is vulnerable to authorization bypass due to type... |
| CVE-2025-14444 | MEDIUM | 5.3 | 0.2% | Feb 18, 2026 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu... |
| CVE-2025-13727 | MEDIUM | 4.4 | 0.3% | Feb 18, 2026 | The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2025-11185 | MEDIUM | 6.4 | 0.2% | Feb 18, 2026 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2025-12356 | MEDIUM | 4.3 | 0.2% | Feb 18, 2026 | The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to unauthorized modification of data due t... |
| CVE-2025-12122 | MEDIUM | 6.4 | 0.2% | Feb 18, 2026 | The Popup Box – Easily Create WordPress Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2025-11737 | MEDIUM | 6.4 | 0.2% | Feb 18, 2026 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_sns... |
| CVE-2025-6460 | MEDIUM | 6.4 | 0.2% | Feb 18, 2026 | The Display During Conditional Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mess... |
| CVE-2025-13959 | MEDIUM | 6.4 | 0.2% | Feb 18, 2026 | The Filestack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'filepicker' shortcode ... |
| CVE-2025-12075 | MEDIUM | 4.3 | 0.2% | Feb 18, 2026 | The Order Splitter for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca... |
| CVE-2025-12074 | MEDIUM | 5.3 | 0.3% | Feb 18, 2026 | The Context Blog theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.5 v... |
| CVE-2025-12071 | MEDIUM | 4.3 | 0.2% | Feb 18, 2026 | The Frontend User Notes plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an... |
| CVE-2025-12037 | MEDIUM | 4.4 | 0.2% | Feb 18, 2026 | The WP 404 Auto Redirect to Similar Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set... |
| CVE-2025-62183 | MEDIUM | 4.8 | 0.3% | Feb 17, 2026 | Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerability in a user interf... |
| CVE-2025-13333 | MEDIUM | 4.9 | 0.3% | Feb 17, 2026 | IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration o... |
| CVE-2025-36348 | MEDIUM | 4.9 | 0.3% | Feb 17, 2026 | IBM Sterling B2B Integrator versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1, an... |
| CVE-2025-33135 | MEDIUM | 6.1 | 0.2% | Feb 17, 2026 | IBM Financial Transaction Manager for ACH Services and Check Services for Multi-Platform 3.0.0.0 through 3.0.5.4 Interim... |
| CVE-2025-14289 | MEDIUM | 5.4 | 0.2% | Feb 17, 2026 | IBM webMethods Integration Server 12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML co... |
| CVE-2025-13691 | MEDIUM | 6.5 | 0.3% | Feb 17, 2026 | IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be ... |
| CVE-2025-36598 | MEDIUM | 6.5 | 0.3% | Feb 17, 2026 | Dell Avamar, versions prior to 19.12 with patch 338905, contains an Improper Limitation of a Pathname to a Restricted Di... |
| CVE-2025-36597 | MEDIUM | 4.7 | 0.3% | Feb 17, 2026 | Dell Avamar, versions prior to 19.12 with patch 338905, contains an Improper Limitation of a Pathname to a Restricted Di... |
| CVE-2025-36243 | MEDIUM | 4.3 | 0.1% | Feb 17, 2026 | IBM Concert 1.0.0 through 2.1.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated att... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now