2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4960 | HIGH | 7.8 | 0.1% | Feb 19, 2026 | The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege esca... |
| CVE-2025-4521 | HIGH | 8.8 | 0.3% | Feb 19, 2026 | The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escala... |
| CVE-2025-15041 | HIGH | 7.2 | 0.4% | Feb 19, 2026 | The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized modification of data... |
| CVE-2025-14452 | HIGH | 7.2 | 0.3% | Feb 19, 2026 | The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' param... |
| CVE-2025-13603 | HIGH | 8.8 | 0.4% | Feb 19, 2026 | The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and i... |
| CVE-2025-12975 | HIGH | 7.2 | 0.8% | Feb 19, 2026 | The CTX Feed – WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin inst... |
| CVE-2025-12845 | HIGH | 8.8 | 0.4% | Feb 19, 2026 | The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to ... |
| CVE-2025-12821 | HIGH | 8.8 | 0.3% | Feb 19, 2026 | The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.6.1. This is... |
| CVE-2025-12707 | HIGH | 7.5 | 0.4% | Feb 19, 2026 | The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all version... |
| CVE-2025-11754 | HIGH | 7.5 | 0.4% | Feb 19, 2026 | The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch... |
| CVE-2025-1272 | HIGH | 7.7 | 0.2% | Feb 18, 2026 | The Linux Kernel lockdown mode for kernel versions starting on 6.12 and above for Fedora Linux has the lockdown mode dis... |
| CVE-2025-70064 | HIGH | 8.8 | 0.5% | Feb 18, 2026 | PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient... |
| CVE-2025-70151 | HIGH | 8.8 | 0.6% | Feb 18, 2026 | code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestr... |
| CVE-2025-70148 | HIGH | 7.5 | 0.4% | Feb 18, 2026 | Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allo... |
| CVE-2025-70147 | HIGH | 7.5 | 0.4% | Feb 18, 2026 | Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 all... |
| CVE-2025-71234 | HIGH | 7.8 | 0.1% | Feb 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtl8xxxu: fix slab-out-of-bounds in rtl8xxxu_... |
| CVE-2025-71231 | HIGH | 7.1 | 0.1% | Feb 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - Fix out-of-bounds index in find_empty... |
| CVE-2025-61982 | HIGH | 7.8 | 0.1% | Feb 18, 2026 | An arbitrary code execution vulnerability exists in the Code Stream directive functionality of OpenCFD OpenFOAM 2506. A ... |
| CVE-2025-60038 | HIGH | 8.8 | 0.3% | Feb 18, 2026 | A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the... |
| CVE-2025-60037 | HIGH | 8.8 | 0.3% | Feb 18, 2026 | A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the... |
| CVE-2025-60036 | HIGH | 8.8 | 0.4% | Feb 18, 2026 | A vulnerability has been identified in the UA.Testclient utility, which is included in Rexroth IndraWorks. All versions ... |
| CVE-2025-60035 | HIGH | 8.8 | 0.4% | Feb 18, 2026 | A vulnerability has been identified in the OPC.Testclient utility, which is included in Rexroth IndraWorks. All versions... |
| CVE-2025-59920 | HIGH | 8.6 | 0.3% | Feb 18, 2026 | When hours are entered in time@work, version 7.0.5, it performs a query to display the projects assigned to the user. If... |
| CVE-2025-33253 | HIGH | 7.3 | 0.2% | Feb 18, 2026 | NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by convincing a user ... |
| CVE-2025-33252 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now