2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59100 | MEDIUM | 5.9 | 0.6% | Jan 26, 2026 | The web interface offers a functionality to export the internal SQLite database. After executing the database export, an... |
| CVE-2025-59096 | MEDIUM | 4.6 | 0.2% | Jan 26, 2026 | The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is... |
| CVE-2025-59095 | MEDIUM | 6.8 | 0.1% | Jan 26, 2026 | The program libraries (DLL) and binaries used by exos 9300 contain multiple hard-coded secrets. One notable example is t... |
| CVE-2025-41083 | MEDIUM | 5.1 | 0.4% | Jan 26, 2026 | Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipu... |
| CVE-2025-41082 | MEDIUM | 6.9 | 0.4% | Jan 26, 2026 | Illegal HTTP request traffic vulnerability (CL.0) in Altitude Communication Server, caused by inconsistent analysis of m... |
| CVE-2025-14973 | MEDIUM | 6.8 | 0.3% | Jan 26, 2026 | The Recipe Card Blocks Lite WordPress plugin before 3.4.13 does not sanitize and escape a parameter before using it in a... |
| CVE-2025-71163 | MEDIUM | 5.5 | 0.2% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix device leaks on compat bind an... |
| CVE-2025-6461 | MEDIUM | 4.3 | 0.2% | Jan 25, 2026 | The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all vers... |
| CVE-2025-13920 | MEDIUM | 5.3 | 0.7% | Jan 24, 2026 | The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc... |
| CVE-2025-15516 | MEDIUM | 4.3 | 0.2% | Jan 24, 2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca... |
| CVE-2025-14907 | MEDIUM | 4.3 | 0.1% | Jan 24, 2026 | The Moderate Selected Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2025-14630 | MEDIUM | 4.3 | 0.2% | Jan 24, 2026 | The AdminQuickbar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-13205 | MEDIUM | 4.3 | 0.1% | Jan 24, 2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for ... |
| CVE-2025-13194 | MEDIUM | 4.3 | 0.1% | Jan 24, 2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for ... |
| CVE-2025-13139 | MEDIUM | 4.3 | 0.1% | Jan 24, 2026 | The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all... |
| CVE-2025-14985 | MEDIUM | 6.4 | 0.2% | Jan 24, 2026 | The Alpha Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alpha_block_css’ parameter i... |
| CVE-2025-14941 | MEDIUM | 6.4 | 0.3% | Jan 24, 2026 | The GZSEO plugin for WordPress is vulnerable to authorization bypass leading to Stored Cross-Site Scripting in all versi... |
| CVE-2025-14906 | MEDIUM | 4.3 | 0.1% | Jan 24, 2026 | The WP Youtube Video Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and... |
| CVE-2025-14903 | MEDIUM | 4.3 | 0.2% | Jan 24, 2026 | The Simple Crypto Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc... |
| CVE-2025-14843 | MEDIUM | 5.3 | 0.3% | Jan 24, 2026 | The Wizit Gateway for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Order Cancellation in ... |
| CVE-2025-14797 | MEDIUM | 5.4 | 0.2% | Jan 24, 2026 | The Same Category Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget title placehold... |
| CVE-2025-14629 | MEDIUM | 5.3 | 0.3% | Jan 24, 2026 | The Alchemist Ajax Upload plugin for WordPress is vulnerable to unauthorized media file deletion due to a missing capabi... |
| CVE-2025-14609 | MEDIUM | 5.3 | 0.3% | Jan 24, 2026 | The Wise Analytics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1... |
| CVE-2025-13676 | MEDIUM | 6.1 | 0.3% | Jan 24, 2026 | The JustClick registration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a... |
| CVE-2025-12836 | MEDIUM | 6.4 | 0.2% | Jan 24, 2026 | The VK Google Job Posting Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Descript... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now