2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26600 | HIGH | 7.8 | 0.4% | Feb 25, 2025 | A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued fo... |
| CVE-2025-26599 | HIGH | 7.8 | 0.4% | Feb 25, 2025 | An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if... |
| CVE-2025-26598 | HIGH | 7.8 | 0.4% | Feb 25, 2025 | An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer de... |
| CVE-2025-26597 | HIGH | 7.8 | 0.5% | Feb 25, 2025 | A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resiz... |
| CVE-2025-26596 | HIGH | 7.8 | 0.4% | Feb 25, 2025 | A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from wha... |
| CVE-2025-26595 | HIGH | 7.8 | 0.4% | Feb 25, 2025 | A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on ... |
| CVE-2025-26594 | HIGH | 7.8 | 0.4% | Feb 25, 2025 | A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variabl... |
| CVE-2025-26993 | HIGH | 7.1 | 0.3% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vito Peleg Atarim ... |
| CVE-2025-26991 | HIGH | 7.1 | 0.3% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ollybach WPPizza w... |
| CVE-2025-26985 | HIGH | 8.1 | 0.7% | Feb 25, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-26981 | HIGH | 7.1 | 0.3% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in accessiBe Web Acce... |
| CVE-2025-26979 | HIGH | 7.5 | 0.7% | Feb 25, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-26977 | HIGH | 7.2 | 0.4% | Feb 25, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Ninja Team Filebird filebird allows Exploiting Incorre... |
| CVE-2025-26964 | HIGH | 8.8 | 0.7% | Feb 25, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-26963 | HIGH | 8.8 | 0.2% | Feb 25, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ClickWhale ClickWhale clickwhale allows Cross Site Request Forgery.Th... |
| CVE-2025-26957 | HIGH | 7.5 | 0.7% | Feb 25, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-26946 | HIGH | 7.6 | 0.4% | Feb 25, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jgwhite33 WP Yelp ... |
| CVE-2025-26935 | HIGH | 8.8 | 0.6% | Feb 25, 2025 | Path Traversal: '.../...//' vulnerability in wpjobportal WP Job Portal wp-job-portal allows PHP Local File Inclusion.Thi... |
| CVE-2025-26932 | HIGH | 7.5 | 0.7% | Feb 25, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-26931 | HIGH | 7.1 | 0.1% | Feb 25, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Software Tribulant Gallery Voting gallery-voting allows Sto... |
| CVE-2025-26915 | HIGH | 8.5 | 0.4% | Feb 25, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PickPlugins Wishli... |
| CVE-2025-26907 | HIGH | 7.5 | 0.4% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Estatik Mortgage C... |
| CVE-2025-26905 | HIGH | 7.5 | 0.5% | Feb 25, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estatik Estatik estatik ... |
| CVE-2025-26871 | HIGH | 8.8 | 0.4% | Feb 25, 2025 | Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Exploiting Inc... |
| CVE-2025-26868 | HIGH | 7.1 | 0.3% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fastflow Fast Flow... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now