2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46699 | MEDIUM | 6.5 | 0.3% | Jan 23, 2026 | Dell Data Protection Advisor, versions prior to 19.12, contains an Improper Neutralization of Special Elements Used in a... |
| CVE-2025-14745 | MEDIUM | 6.4 | 0.2% | Jan 23, 2026 | The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Stored... |
| CVE-2025-14069 | MEDIUM | 6.4 | 0.2% | Jan 23, 2026 | The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sas... |
| CVE-2025-15522 | MEDIUM | 6.4 | 0.3% | Jan 23, 2026 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnera... |
| CVE-2025-9290 | MEDIUM | 5.9 | 0.2% | Jan 23, 2026 | An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption d... |
| CVE-2025-67652 | MEDIUM | 6.1 | 0.1% | Jan 22, 2026 | An attacker with access to the project file could use the exposed credentials to impersonate users, escalate privileges... |
| CVE-2025-25051 | MEDIUM | 6.1 | 0.1% | Jan 22, 2026 | An attacker could decrypt sensitive data, impersonate legitimate users or devices, and potentially gain access to netwo... |
| CVE-2025-9289 | MEDIUM | 4.7 | 0.2% | Jan 22, 2026 | A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sani... |
| CVE-2025-22234 | MEDIUM | 5.3 | 0.4% | Jan 22, 2026 | The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvi... |
| CVE-2025-68609 | MEDIUM | 6.6 | 0.4% | Jan 22, 2026 | A vulnerability in Palantir's Aries service allowed unauthenticated access to log viewing and management functionality o... |
| CVE-2025-70899 | MEDIUM | 6.5 | 0.1% | Jan 22, 2026 | PHPgurukul Online Course Registration v3.1 lacks Cross-Site Request Forgery (CSRF) protection on all administrative form... |
| CVE-2025-69315 | MEDIUM | 6.5 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploit... |
| CVE-2025-69300 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor allows Exploitin... |
| CVE-2025-69095 | MEDIUM | 6.5 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in designthemes Reservation Plugin dt-reservation-plugin allows Exploiting Incorrect... |
| CVE-2025-69055 | MEDIUM | 6.5 | 0.3% | Jan 22, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SeaTheme BM Content Buil... |
| CVE-2025-69001 | MEDIUM | 5.3 | 0.2% | Jan 22, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Shahjahan Jewel FluentForm fluentform allows ... |
| CVE-2025-68911 | MEDIUM | 6.5 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in solacewp Solace solace allows Exploiting Incorrectly Configured Access Control Se... |
| CVE-2025-68900 | MEDIUM | 6.5 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold allo... |
| CVE-2025-68898 | MEDIUM | 5.8 | 0.1% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cjjparadoxmax Syne... |
| CVE-2025-68896 | MEDIUM | 6.5 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in vrpr WDV One Page Docs wdv-one-page-docs allows Exploiting Incorrectly Configured... |
| CVE-2025-68558 | MEDIUM | 6.5 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in averta Depicter Slider depicter allows Exploiting Incorrectly Configured Access C... |
| CVE-2025-68507 | MEDIUM | 6.5 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in Icegram Icegram icegram allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2025-68073 | MEDIUM | 6.5 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in Ninja Team GDPR CCPA Compliance Support ninja-gdpr-compliance allows Exploiting I... |
| CVE-2025-68072 | MEDIUM | 6.5 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in Merv Barrett Easy Property Listings easy-property-listings allows Exploiting Inco... |
| CVE-2025-68046 | MEDIUM | 6.5 | 0.4% | Jan 22, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThemeHunk Contact Form & Lea... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now