2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71200 | MEDIUM | 5.5 | 0.1% | Feb 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci-of-dwcmshc: Prevent illegal clock reduct... |
| CVE-2025-6792 | MEDIUM | 5.3 | 0.3% | Feb 14, 2026 | The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing c... |
| CVE-2025-15483 | MEDIUM | 4.4 | 0.2% | Feb 14, 2026 | The Link Hopper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hop_name’ parameter in all ve... |
| CVE-2025-14873 | MEDIUM | 4.3 | 0.1% | Feb 14, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Req... |
| CVE-2025-14852 | MEDIUM | 4.3 | 0.2% | Feb 14, 2026 | The MDirector Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2025-14608 | MEDIUM | 5.3 | 0.2% | Feb 14, 2026 | The WP Last Modified Info plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, ... |
| CVE-2025-14067 | MEDIUM | 5.3 | 0.2% | Feb 14, 2026 | The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability chec... |
| CVE-2025-13973 | MEDIUM | 5.3 | 0.3% | Feb 14, 2026 | The StickEasy Protected Contact Form plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versi... |
| CVE-2025-13681 | MEDIUM | 4.9 | 0.4% | Feb 14, 2026 | The BFG Tools – Extension Zipper plugin for WordPress is vulnerable to Path Traversal in all versions up to, and includi... |
| CVE-2025-66676 | MEDIUM | 6.2 | 0.2% | Feb 13, 2026 | An issue in IObit Unlocker v1.3.0.11 allows attackers to cause a Denial of Service (DoS) via a crafted request. |
| CVE-2025-1790 | MEDIUM | 5.8 | 0.1% | Feb 13, 2026 | Local privilege escalation in Genetec Sipelia Plugin. An authenticated low-privileged Windows user could exploit this vu... |
| CVE-2025-70095 | MEDIUM | 6.5 | 0.2% | Feb 13, 2026 | A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 all... |
| CVE-2025-70094 | MEDIUM | 6.5 | 0.2% | Feb 13, 2026 | A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attacker... |
| CVE-2025-70091 | MEDIUM | 6.5 | 0.2% | Feb 13, 2026 | A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute... |
| CVE-2025-48023 | MEDIUM | 6.5 | 0.2% | Feb 13, 2026 | A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ... |
| CVE-2025-48022 | MEDIUM | 6.5 | 0.2% | Feb 13, 2026 | A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ... |
| CVE-2025-48021 | MEDIUM | 6.5 | 0.2% | Feb 13, 2026 | A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ... |
| CVE-2025-15520 | MEDIUM | 4.3 | 0.2% | Feb 13, 2026 | The RegistrationMagic WordPress plugin before 6.0.7.2 checks nonces but not capabilities, allowing for the disclosure o... |
| CVE-2025-48020 | MEDIUM | 6.5 | 0.2% | Feb 13, 2026 | A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ... |
| CVE-2025-48019 | MEDIUM | 6.5 | 0.2% | Feb 13, 2026 | A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ... |
| CVE-2025-70092 | MEDIUM | 5.5 | 0.2% | Feb 12, 2026 | A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute... |
| CVE-2025-70845 | MEDIUM | 6.1 | 0.2% | Feb 12, 2026 | lty628 aidigu v1.9.1 is vulnerable to Cross Site Scripting (XSS) exists in the /setting/ page where the "intro" field is... |
| CVE-2025-14282 | MEDIUM | 5.4 | 0.4% | Feb 12, 2026 | A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the... |
| CVE-2025-69752 | MEDIUM | 4.3 | 0.2% | Feb 12, 2026 | An issue in the "My Details" user profile functionality of Ideagen Q-Pulse 7.1.0.32 allows an authenticated user to view... |
| CVE-2025-56647 | MEDIUM | 6.5 | 0.2% | Feb 12, 2026 | npm @farmfe/core before 1.7.6 is Missing Origin Validation in WebSocket. The development (hot module reloading) server d... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now