2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70368 | MEDIUM | 5.4 | 0.2% | Jan 26, 2026 | Worklenz version 2.1.5 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Project Updates feature. An att... |
| CVE-2025-57785 | MEDIUM | 6.5 | 0.3% | Jan 26, 2026 | A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which allows an unauthenticate... |
| CVE-2025-57783 | MEDIUM | 5.3 | 0.4% | Jan 26, 2026 | Improper header parsing may lead to request smuggling has been identified in Hiawatha webserver version 11.7 which allow... |
| CVE-2025-50537 | MEDIUM | 5.5 | 0.2% | Jan 26, 2026 | Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/sha... |
| CVE-2025-59109 | MEDIUM | 5.1 | 0.5% | Jan 26, 2026 | The dormakaba registration units 9002 (PIN Pad Units) have an exposed UART header on the backside. The PIN pad is sendin... |
| CVE-2025-59102 | MEDIUM | 6.9 | 0.3% | Jan 26, 2026 | The web server of the Access Manager offers a functionality to download a backup of the local database stored on the dev... |
| CVE-2025-59100 | MEDIUM | 5.9 | 0.6% | Jan 26, 2026 | The web interface offers a functionality to export the internal SQLite database. After executing the database export, an... |
| CVE-2025-59096 | MEDIUM | 4.6 | 0.2% | Jan 26, 2026 | The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is... |
| CVE-2025-59095 | MEDIUM | 6.8 | 0.1% | Jan 26, 2026 | The program libraries (DLL) and binaries used by exos 9300 contain multiple hard-coded secrets. One notable example is t... |
| CVE-2025-41083 | MEDIUM | 5.1 | 0.4% | Jan 26, 2026 | Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipu... |
| CVE-2025-41082 | MEDIUM | 6.9 | 0.4% | Jan 26, 2026 | Illegal HTTP request traffic vulnerability (CL.0) in Altitude Communication Server, caused by inconsistent analysis of m... |
| CVE-2025-14973 | MEDIUM | 6.8 | 0.3% | Jan 26, 2026 | The Recipe Card Blocks Lite WordPress plugin before 3.4.13 does not sanitize and escape a parameter before using it in a... |
| CVE-2025-71163 | MEDIUM | 5.5 | 0.2% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix device leaks on compat bind an... |
| CVE-2025-6461 | MEDIUM | 4.3 | 0.2% | Jan 25, 2026 | The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all vers... |
| CVE-2025-13920 | MEDIUM | 5.3 | 0.7% | Jan 24, 2026 | The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc... |
| CVE-2025-15516 | MEDIUM | 4.3 | 0.2% | Jan 24, 2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca... |
| CVE-2025-14907 | MEDIUM | 4.3 | 0.1% | Jan 24, 2026 | The Moderate Selected Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2025-14630 | MEDIUM | 4.3 | 0.2% | Jan 24, 2026 | The AdminQuickbar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-13205 | MEDIUM | 4.3 | 0.1% | Jan 24, 2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for ... |
| CVE-2025-13194 | MEDIUM | 4.3 | 0.1% | Jan 24, 2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for ... |
| CVE-2025-13139 | MEDIUM | 4.3 | 0.1% | Jan 24, 2026 | The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all... |
| CVE-2025-14985 | MEDIUM | 6.4 | 0.2% | Jan 24, 2026 | The Alpha Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alpha_block_css’ parameter i... |
| CVE-2025-14941 | MEDIUM | 6.4 | 0.3% | Jan 24, 2026 | The GZSEO plugin for WordPress is vulnerable to authorization bypass leading to Stored Cross-Site Scripting in all versi... |
| CVE-2025-14906 | MEDIUM | 4.3 | 0.1% | Jan 24, 2026 | The WP Youtube Video Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and... |
| CVE-2025-14903 | MEDIUM | 4.3 | 0.2% | Jan 24, 2026 | The Simple Crypto Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now