2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63051 | MEDIUM | 4.3 | 0.3% | Jan 22, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in sizam REHub Framework rehub-... |
| CVE-2025-63026 | MEDIUM | 6.5 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand R... |
| CVE-2025-63019 | MEDIUM | 5.3 | 0.4% | Jan 22, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Johan Jonk Stenström Cookies and Content Security Pol... |
| CVE-2025-63018 | MEDIUM | 4.3 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in wproyal Bard bard allows Exploiting Incorrectly Configured Access Control Securit... |
| CVE-2025-62754 | MEDIUM | 5.3 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in Kapil Paul Payment Gateway bKash for WC woo-payment-bkash allows Exploiting Incor... |
| CVE-2025-62741 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Pool Services pool-services allows Server Side Request... |
| CVE-2025-62106 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in Mario Peshev WP-CRM System wp-crm-system allows Exploiting Incorrectly Configured... |
| CVE-2025-62077 | MEDIUM | 5.9 | 0.3% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SEOSEON EUROPE S.L... |
| CVE-2025-5805 | MEDIUM | 6.5 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in Ninetheme Electron electron allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2025-54002 | MEDIUM | 6.5 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in Jthemes xSmart xsmart allows Exploiting Incorrectly Configured Access Control Sec... |
| CVE-2025-50005 | MEDIUM | 6.5 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Comp... |
| CVE-2025-49375 | MEDIUM | 5.4 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in cozythemes HomeLancer homelancer allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-49336 | MEDIUM | 5.9 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pondol Pondol BBS ... |
| CVE-2025-47600 | MEDIUM | 5.3 | 0.3% | Jan 22, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in xtemos WoodMart woodmart ... |
| CVE-2025-47500 | MEDIUM | 5.9 | 0.3% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Intal Sta... |
| CVE-2025-31413 | MEDIUM | 4.3 | 0.1% | Jan 22, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in bdthemes Element Pack Elementor Addons bdthemes-element-pack-lite all... |
| CVE-2025-69820 | MEDIUM | 6 | 0.9% | Jan 22, 2026 | Directory Traversal vulnerability in Beam beta9 v.0.1.521 allows a remote attacker to obtain sensitive information via t... |
| CVE-2025-69612 | MEDIUM | 6.5 | 0.9% | Jan 22, 2026 | A path traversal vulnerability exists in TMS Management Console (version 6.3.7.27386.20250818) from TMS Global Software.... |
| CVE-2025-32057 | MEDIUM | 6.5 | 0.3% | Jan 22, 2026 | The Infotainment ECU manufactured by Bosch which is installed in Nissan Leaf ZE1 – 2020 uses a Redbend service for over-... |
| CVE-2025-32056 | MEDIUM | 4 | 0.3% | Jan 22, 2026 | The anti-theft protection mechanism can be bypassed by attackers due to weak response generation algorithms for the head... |
| CVE-2025-15523 | MEDIUM | 4.8 | 0.1% | Jan 22, 2026 | MacOS version of Inkscape bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permis... |
| CVE-2025-67683 | MEDIUM | 6.1 | 0.3% | Jan 22, 2026 | Quick.Cart is vulnerable to reflected XSS via the sSort parameter. An attacker can craft a malicious URL which, when ope... |
| CVE-2025-4763 | MEDIUM | 6.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aida Comput... |
| CVE-2025-13335 | MEDIUM | 6.5 | 0.5% | Jan 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.4, 18.7 before 18.7.2, and 1... |
| CVE-2025-71176 | MEDIUM | 6.8 | 0.1% | Jan 22, 2026 | pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now