2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67723 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have a cont... |
| CVE-2025-66488 | MEDIUM | 6.1 | 0.2% | Jan 28, 2026 | Discourse is an open source discussion platform. A vulnerability present in versions prior to 3.5.4, 2025.11.2, 2025.12.... |
| CVE-2025-57796 | MEDIUM | 6.8 | 0.2% | Jan 28, 2026 | Explorance Blue versions prior to 8.14.12 use reversible symmetric encryption with a hardcoded static key to protect sen... |
| CVE-2025-46316 | MEDIUM | 4.3 | 0.3% | Jan 28, 2026 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in Pages 15.1, iOS 26.1 and iPad... |
| CVE-2025-46306 | MEDIUM | 5.5 | 0.1% | Jan 28, 2026 | The issue was addressed with improved bounds checks. This issue is fixed in Keynote 15.1, iOS 26 and iPadOS 26, macOS Ta... |
| CVE-2025-33237 | MEDIUM | 5.5 | 0.1% | Jan 28, 2026 | NVIDIA HD Audio Driver for Windows contains a vulnerability where an attacker could exploit a NULL pointer dereference i... |
| CVE-2025-65887 | MEDIUM | 6.5 | 0.3% | Jan 28, 2026 | A division-by-zero vulnerability in the flow.floor_divide() component of OneFlow v0.9.0 allows attackers to cause a Deni... |
| CVE-2025-13919 | MEDIUM | 4.4 | 0.1% | Jan 28, 2026 | Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a COM Hija... |
| CVE-2025-13918 | MEDIUM | 6.7 | 0.1% | Jan 28, 2026 | Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevatio... |
| CVE-2025-70336 | MEDIUM | 4.8 | 0.2% | Jan 28, 2026 | A Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote atta... |
| CVE-2025-14795 | MEDIUM | 4.3 | 0.2% | Jan 28, 2026 | The Stop Spammers Classic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-14865 | MEDIUM | 6.4 | 0.2% | Jan 28, 2026 | The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2025-59900 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ... |
| CVE-2025-59899 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ... |
| CVE-2025-59898 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ... |
| CVE-2025-59897 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ... |
| CVE-2025-59896 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ... |
| CVE-2025-15511 | MEDIUM | 5.3 | 0.2% | Jan 28, 2026 | The Rupantorpay plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec... |
| CVE-2025-14616 | MEDIUM | 4.3 | 0.1% | Jan 28, 2026 | The Recooty – Job Widget (Old Dashboard) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version... |
| CVE-2025-14283 | MEDIUM | 6.4 | 0.2% | Jan 28, 2026 | The BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library plugin ... |
| CVE-2025-14063 | MEDIUM | 6.1 | 0.2% | Jan 28, 2026 | The SEO Links Interlinking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'google_error' p... |
| CVE-2025-41351 | MEDIUM | 6 | 0.2% | Jan 28, 2026 | Vulnerability that allows a Padding Oracle Attack to be performed on the Funambol v30.0.0.20 cloud server. The thumbnail... |
| CVE-2025-9082 | MEDIUM | 6.4 | 0.3% | Jan 28, 2026 | The WPBITS Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widget pa... |
| CVE-2025-14039 | MEDIUM | 6.4 | 0.3% | Jan 28, 2026 | The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_simple_folio_item_client_na... |
| CVE-2025-12709 | MEDIUM | 6.4 | 0.2% | Jan 28, 2026 | The Interactions – Create Interactive Experiences in the Block Editor plugin for WordPress is vulnerable to Stored Cross... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now