2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65887 | MEDIUM | 6.5 | 0.3% | Jan 28, 2026 | A division-by-zero vulnerability in the flow.floor_divide() component of OneFlow v0.9.0 allows attackers to cause a Deni... |
| CVE-2025-13919 | MEDIUM | 4.4 | 0.1% | Jan 28, 2026 | Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a COM Hija... |
| CVE-2025-13918 | MEDIUM | 6.7 | 0.1% | Jan 28, 2026 | Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevatio... |
| CVE-2025-70336 | MEDIUM | 4.8 | 0.2% | Jan 28, 2026 | A Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote atta... |
| CVE-2025-14795 | MEDIUM | 4.3 | 0.2% | Jan 28, 2026 | The Stop Spammers Classic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-14865 | MEDIUM | 6.4 | 0.2% | Jan 28, 2026 | The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2025-59900 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ... |
| CVE-2025-59899 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ... |
| CVE-2025-59898 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ... |
| CVE-2025-59897 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ... |
| CVE-2025-59896 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ... |
| CVE-2025-15511 | MEDIUM | 5.3 | 0.2% | Jan 28, 2026 | The Rupantorpay plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec... |
| CVE-2025-14616 | MEDIUM | 4.3 | 0.1% | Jan 28, 2026 | The Recooty – Job Widget (Old Dashboard) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version... |
| CVE-2025-14283 | MEDIUM | 6.4 | 0.2% | Jan 28, 2026 | The BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library plugin ... |
| CVE-2025-14063 | MEDIUM | 6.1 | 0.2% | Jan 28, 2026 | The SEO Links Interlinking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'google_error' p... |
| CVE-2025-41351 | MEDIUM | 6 | 0.2% | Jan 28, 2026 | Vulnerability that allows a Padding Oracle Attack to be performed on the Funambol v30.0.0.20 cloud server. The thumbnail... |
| CVE-2025-9082 | MEDIUM | 6.4 | 0.3% | Jan 28, 2026 | The WPBITS Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widget pa... |
| CVE-2025-14039 | MEDIUM | 6.4 | 0.3% | Jan 28, 2026 | The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_simple_folio_item_client_na... |
| CVE-2025-12709 | MEDIUM | 6.4 | 0.2% | Jan 28, 2026 | The Interactions – Create Interactive Experiences in the Block Editor plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2025-8072 | MEDIUM | 6.4 | 0.2% | Jan 28, 2026 | The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder_img... |
| CVE-2025-13471 | MEDIUM | 5.3 | 0.3% | Jan 28, 2026 | The User Activity Log WordPress plugin through 2.2 does not properly handle failed login attempts in some cases, allowin... |
| CVE-2025-54373 | MEDIUM | 6.5 | 0.4% | Jan 28, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ... |
| CVE-2025-12810 | MEDIUM | 6.5 | 0.4% | Jan 27, 2026 | Improper Authentication vulnerability in Delinea Inc. Secret Server On-Prem (RPC Password Rotation modules).This issue a... |
| CVE-2025-65264 | MEDIUM | 5.5 | 0.2% | Jan 27, 2026 | The kernel driver of CPUID CPU-Z v2.17 and earlier does not validate user-supplied values passed via its IOCTL interface... |
| CVE-2025-69418 | MEDIUM | 4 | 0.1% | Jan 27, 2026 | Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now