2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15324 | MEDIUM | 6.6 | 0.2% | Feb 5, 2026 | Tanium addressed a documentation issue in Engage. |
| CVE-2025-58190 | MEDIUM | 5.3 | 0.5% | Feb 5, 2026 | The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can ... |
| CVE-2025-47911 | MEDIUM | 5.3 | 0.5% | Feb 5, 2026 | The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which ... |
| CVE-2025-15551 | MEDIUM | 5.6 | 0.4% | Feb 5, 2026 | The response coming from TP-Link Archer MR200 v5.2, C20 v5 and v6, TL-WR850N v3, and TL-WR845N v4 for any request is get... |
| CVE-2025-70792 | MEDIUM | 6.1 | 0.3% | Feb 5, 2026 | Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipu... |
| CVE-2025-70791 | MEDIUM | 6.1 | 0.3% | Feb 5, 2026 | Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipu... |
| CVE-2025-69619 | MEDIUM | 5.5 | 0.2% | Feb 5, 2026 | A path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the i... |
| CVE-2025-68643 | MEDIUM | 5.4 | 0.2% | Feb 5, 2026 | Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account pre... |
| CVE-2025-14150 | MEDIUM | 6.5 | 0.3% | Feb 5, 2026 | IBM webMethods Integration (on prem) - Integration Server 10.15 through IS_10.15_Core_Fix2411.1 to IS_11.1_Core_Fix8 IBM... |
| CVE-2025-13491 | MEDIUM | 5.1 | 0.1% | Feb 5, 2026 | IBM App Connect Enterprise Certified Container CD: 11.2.0 through 11.6.0, 12.1.0 through 12.19.0 and 12.0 LTS: 12.0.0 th... |
| CVE-2025-14079 | MEDIUM | 5.3 | 0.3% | Feb 5, 2026 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in a... |
| CVE-2025-13416 | MEDIUM | 4.3 | 0.3% | Feb 5, 2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspensi... |
| CVE-2025-10258 | MEDIUM | 6.3 | 0.3% | Feb 5, 2026 | Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may r... |
| CVE-2025-68699 | MEDIUM | 6.5 | 0.3% | Feb 4, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, NanoMQ has a protocol parsing /... |
| CVE-2025-70545 | MEDIUM | 6.1 | 0.4% | Feb 4, 2026 | A stored cross-site scripting (XSS) vulnerability exists in the web management interface of the PPC (Belden) ONT 2K05X r... |
| CVE-2025-70997 | MEDIUM | 6.5 | 0.2% | Feb 4, 2026 | A vulnerability has been discovered in eladmin v2.7 and before. This vulnerability allows for an arbitrary user password... |
| CVE-2025-69618 | MEDIUM | 6.5 | 0.3% | Feb 4, 2026 | An arbitrary file overwrite vulnerability in the file import process of Tarot, Astro & Healing v11.4.0 allows attackers ... |
| CVE-2025-14740 | MEDIUM | 6.7 | 0.2% | Feb 4, 2026 | Docker Desktop for Windows contains multiple incorrect permission assignment vulnerabilities in the installer's handling... |
| CVE-2025-41085 | MEDIUM | 5.1 | 0.2% | Feb 4, 2026 | Stored Cross-Site Scripting (XSS) vulnerability type in Apidog in the version 2.7.15, where SVG image uploads are not p... |
| CVE-2025-15508 | MEDIUM | 5.3 | 0.3% | Feb 4, 2026 | The Magic Import Document Extractor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions... |
| CVE-2025-15507 | MEDIUM | 5.3 | 0.3% | Feb 4, 2026 | The Magic Import Document Extractor plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2025-15487 | MEDIUM | 4.9 | 0.4% | Feb 4, 2026 | The Code Explorer plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.6 via t... |
| CVE-2025-15482 | MEDIUM | 5.3 | 0.3% | Feb 4, 2026 | The Chapa Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in... |
| CVE-2025-15260 | MEDIUM | 6.5 | 0.3% | Feb 4, 2026 | The MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress is vulnerable to missing authorization i... |
| CVE-2025-14461 | MEDIUM | 5.3 | 0.3% | Feb 4, 2026 | The Xendit Payment plugin for WordPress is vulnerable to unauthorized order status manipulation in all versions up to, a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now