2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15147 | MEDIUM | 4.3 | 0.3% | Feb 10, 2026 | The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure... |
| CVE-2025-15318 | MEDIUM | 6 | 0.2% | Feb 9, 2026 | Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpoint Tools. |
| CVE-2025-15317 | MEDIUM | 6.5 | 0.3% | Feb 9, 2026 | Tanium addressed an uncontrolled resource consumption vulnerability in Tanium Server. |
| CVE-2025-14778 | MEDIUM | 5.4 | 0.3% | Feb 9, 2026 | A flaw was found in Keycloak. A significant Broken Access Control vulnerability exists in the UserManagedPermissionServi... |
| CVE-2025-63354 | MEDIUM | 4.8 | 0.2% | Feb 9, 2026 | Hitron HI3120 v7.2.4.5.2b1 allows stored XSS via the Parental Control option when creating a new filter. The device fail... |
| CVE-2025-59024 | MEDIUM | 6.5 | 0.1% | Feb 9, 2026 | Crafted delegations or IP fragments can poison cached delegations in Recursor. |
| CVE-2025-14831 | MEDIUM | 5.3 | 0.6% | Feb 9, 2026 | A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Uni... |
| CVE-2025-10464 | MEDIUM | 6.5 | 0.2% | Feb 9, 2026 | Insecure Storage of Sensitive Information vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. ... |
| CVE-2025-7708 | MEDIUM | 6.8 | 0.3% | Feb 9, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Atlas Educational Software Industry Ltd. Co. K12net a... |
| CVE-2025-66596 | MEDIUM | 6.1 | 0.2% | Feb 9, 2026 | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properl... |
| CVE-2025-66595 | MEDIUM | 5.4 | 0.1% | Feb 9, 2026 | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product is vulnerable to... |
| CVE-2025-66594 | MEDIUM | 5.3 | 0.2% | Feb 9, 2026 | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Detailed messages are displayed... |
| CVE-2025-66607 | MEDIUM | 5.3 | 0.2% | Feb 9, 2026 | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The response header contains ... |
| CVE-2025-66605 | MEDIUM | 5.3 | 0.2% | Feb 9, 2026 | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Since there are input fields ... |
| CVE-2025-66604 | MEDIUM | 5.3 | 0.1% | Feb 9, 2026 | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The library version could be ... |
| CVE-2025-66601 | MEDIUM | 6.1 | 0.2% | Feb 9, 2026 | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not specify... |
| CVE-2025-66599 | MEDIUM | 6.9 | 0.3% | Feb 9, 2026 | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Physical paths could be displ... |
| CVE-2025-15564 | MEDIUM | 5.5 | 0.2% | Feb 7, 2026 | A vulnerability has been found in Mapnik up to 4.2.0. This vulnerability affects the function mapnik::detail::mod<...>::... |
| CVE-2025-15477 | MEDIUM | 6.5 | 0.2% | Feb 7, 2026 | The Bucketlister plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode `category` and `id` attr... |
| CVE-2025-15476 | MEDIUM | 4.3 | 0.2% | Feb 7, 2026 | The The Bucketlister plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2025-15491 | MEDIUM | 5.5 | 0.3% | Feb 7, 2026 | The Post Slides WordPress plugin through 1.0.1 does not validate some shortcode attributes before using them to generate... |
| CVE-2025-15267 | MEDIUM | 6.4 | 0.2% | Feb 7, 2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_accordion... |
| CVE-2025-13463 | MEDIUM | 6.4 | 0.2% | Feb 7, 2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Grid component in a... |
| CVE-2025-12803 | MEDIUM | 6.4 | 0.2% | Feb 7, 2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bt_bb_tabs' shor... |
| CVE-2025-12159 | MEDIUM | 6.4 | 0.2% | Feb 7, 2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_raw_conte... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now