2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14843 | MEDIUM | 5.3 | 0.3% | Jan 24, 2026 | The Wizit Gateway for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Order Cancellation in ... |
| CVE-2025-14797 | MEDIUM | 5.4 | 0.2% | Jan 24, 2026 | The Same Category Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget title placehold... |
| CVE-2025-14629 | MEDIUM | 5.3 | 0.3% | Jan 24, 2026 | The Alchemist Ajax Upload plugin for WordPress is vulnerable to unauthorized media file deletion due to a missing capabi... |
| CVE-2025-14609 | MEDIUM | 5.3 | 0.3% | Jan 24, 2026 | The Wise Analytics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1... |
| CVE-2025-13676 | MEDIUM | 6.1 | 0.3% | Jan 24, 2026 | The JustClick registration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a... |
| CVE-2025-12836 | MEDIUM | 6.4 | 0.2% | Jan 24, 2026 | The VK Google Job Posting Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Descript... |
| CVE-2025-70458 | MEDIUM | 5.4 | 0.2% | Jan 23, 2026 | A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sou... |
| CVE-2025-52023 | MEDIUM | 5.3 | 0.4% | Jan 23, 2026 | A vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to t... |
| CVE-2025-52022 | MEDIUM | 5.3 | 0.4% | Jan 23, 2026 | A vulnerability in the PHP backend of gemsloyalty.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers ... |
| CVE-2025-14947 | MEDIUM | 6.5 | 0.4% | Jan 23, 2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca... |
| CVE-2025-71177 | MEDIUM | 5.4 | 0.2% | Jan 23, 2026 | LavaLite CMS versions up to and including 10.1.0 contain a stored cross-site scripting vulnerability in the package crea... |
| CVE-2025-67231 | MEDIUM | 5.9 | 0.3% | Jan 23, 2026 | A reflected cross-site scripting (XSS) vulnerability in ToDesktop Builder v0.33.1 allows attackers to execute arbitrary ... |
| CVE-2025-71161 | MEDIUM | 5.5 | 0.2% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm-verity: disable recursive forward error correcti... |
| CVE-2025-71160 | MEDIUM | 5.5 | 0.2% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: avoid chain re-validation if ... |
| CVE-2025-71158 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: gpio: mpsse: ensure worker is torn down When an IR... |
| CVE-2025-67125 | MEDIUM | 4.4 | 0.2% | Jan 23, 2026 | A signed integer overflow in docopt.cpp v0.6.2 (LeafPattern::match in docopt_private.h) when merging occurrence counters... |
| CVE-2025-67124 | MEDIUM | 6.8 | 0.3% | Jan 23, 2026 | A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an atta... |
| CVE-2025-71154 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix memory leak on usb_submit_ur... |
| CVE-2025-71153 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix memory leak in get_file_all_info() In g... |
| CVE-2025-71151 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory and information leak in smb3_recon... |
| CVE-2025-71150 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix refcount leak when invalid session is fo... |
| CVE-2025-71147 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix a memory leak in tpm2_load_cmd ... |
| CVE-2025-71146 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: fix leaked ct in error pat... |
| CVE-2025-13921 | MEDIUM | 4.3 | 0.3% | Jan 23, 2026 | The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to unau... |
| CVE-2025-2204 | MEDIUM | 4.7 | 0.3% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tapandsign ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now