2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8072 | MEDIUM | 6.4 | 0.2% | Jan 28, 2026 | The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder_img... |
| CVE-2025-13471 | MEDIUM | 5.3 | 0.3% | Jan 28, 2026 | The User Activity Log WordPress plugin through 2.2 does not properly handle failed login attempts in some cases, allowin... |
| CVE-2025-54373 | MEDIUM | 6.5 | 0.4% | Jan 28, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ... |
| CVE-2025-12810 | MEDIUM | 6.5 | 0.4% | Jan 27, 2026 | Improper Authentication vulnerability in Delinea Inc. Secret Server On-Prem (RPC Password Rotation modules).This issue a... |
| CVE-2025-65264 | MEDIUM | 5.5 | 0.2% | Jan 27, 2026 | The kernel driver of CPUID CPU-Z v2.17 and earlier does not validate user-supplied values passed via its IOCTL interface... |
| CVE-2025-69418 | MEDIUM | 4 | 0.1% | Jan 27, 2026 | Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs... |
| CVE-2025-68160 | MEDIUM | 4.7 | 0.2% | Jan 27, 2026 | Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO perf... |
| CVE-2025-66199 | MEDIUM | 5.9 | 0.4% | Jan 27, 2026 | Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decomp... |
| CVE-2025-28164 | MEDIUM | 5.5 | 0.1% | Jan 27, 2026 | Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_creat... |
| CVE-2025-28162 | MEDIUM | 5.5 | 0.1% | Jan 27, 2026 | Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngim... |
| CVE-2025-15469 | MEDIUM | 5.5 | 0.2% | Jan 27, 2026 | Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing al... |
| CVE-2025-15468 | MEDIUM | 5.9 | 0.7% | Jan 27, 2026 | Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an un... |
| CVE-2025-11187 | MEDIUM | 6.1 | 0.5% | Jan 27, 2026 | Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow... |
| CVE-2025-41728 | MEDIUM | 5.3 | 0.3% | Jan 27, 2026 | A low privileged remote attacker may be able to disclose confidential information from the memory of a privileged proces... |
| CVE-2025-12387 | MEDIUM | 6.9 | 0.7% | Jan 27, 2026 | A vulnerability in the Pix-Link LV-WR21Q router's language module allows remote attackers to trigger a denial of service... |
| CVE-2025-12386 | MEDIUM | 6.9 | 0.7% | Jan 27, 2026 | Pix-Link LV-WR21Q does not enforce any form of authentication for endpoint /goform/getHomePageInfo. Remote unauthenticat... |
| CVE-2025-14971 | MEDIUM | 5.3 | 0.3% | Jan 27, 2026 | The Link Invoice Payment for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to ... |
| CVE-2025-9820 | MEDIUM | 4 | 0.2% | Jan 26, 2026 | A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 tok... |
| CVE-2025-9522 | MEDIUM | 5.3 | 0.2% | Jan 26, 2026 | Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests t... |
| CVE-2025-9521 | MEDIUM | 6.5 | 0.3% | Jan 26, 2026 | Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypa... |
| CVE-2025-9520 | MEDIUM | 6.8 | 0.4% | Jan 26, 2026 | An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate r... |
| CVE-2025-14969 | MEDIUM | 4.3 | 0.4% | Jan 26, 2026 | A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client... |
| CVE-2025-14525 | MEDIUM | 6.4 | 0.3% | Jan 26, 2026 | A flaw was found in kubevirt. A user within a virtual machine (VM), if the guest agent is active, can exploit this by ca... |
| CVE-2025-11687 | MEDIUM | 6.1 | 0.3% | Jan 26, 2026 | A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page —... |
| CVE-2025-11065 | MEDIUM | 5.3 | 0.4% | Jan 26, 2026 | A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now