2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26753 | HIGH | 7.5 | 0.5% | Feb 25, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Broadcast L... |
| CVE-2025-26752 | HIGH | 8.6 | 0.5% | Feb 25, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Broadcast L... |
| CVE-2025-26751 | HIGH | 7.1 | 0.3% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood Alph... |
| CVE-2025-1674 | HIGH | 8.2 | 0.3% | Feb 25, 2025 | A lack of input validation allows for out of bounds reads caused by malicious or malformed packets. |
| CVE-2025-1673 | HIGH | 8.2 | 0.3% | Feb 25, 2025 | A malicious or malformed DNS packet without a payload can cause an out-of-bounds read, resulting in a crash (denial of s... |
| CVE-2025-1648 | HIGH | 7.5 | 0.8% | Feb 25, 2025 | The Yawave plugin for WordPress is vulnerable to SQL Injection via the 'lbid' parameter in all versions up to, and inclu... |
| CVE-2025-22210 | HIGH | 7.2 | 0.5% | Feb 25, 2025 | A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (... |
| CVE-2025-1646 | HIGH | 7.3 | 0.4% | Feb 25, 2025 | A vulnerability, which was classified as critical, has been found in Lumsoft ERP 8. Affected by this issue is some unkno... |
| CVE-2025-1643 | HIGH | 8.8 | 0.3% | Feb 25, 2025 | A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been rated as problematic. This issue affects some un... |
| CVE-2025-1642 | HIGH | 7.5 | 0.6% | Feb 25, 2025 | A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been declared as critical. This vulnerability affects... |
| CVE-2025-26525 | HIGH | 8.6 | 0.4% | Feb 24, 2025 | Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is ava... |
| CVE-2025-27133 | HIGH | 8.8 | 0.5% | Feb 24, 2025 | WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio... |
| CVE-2025-26200 | HIGH | 7.2 | 0.5% | Feb 24, 2025 | SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_re... |
| CVE-2025-22495 | HIGH | 8.4 | 0.4% | Feb 24, 2025 | An improper input validation vulnerability was discovered in the NTP server configuration field of the Network-M2 card. ... |
| CVE-2025-26803 | HIGH | 7.5 | 0.6% | Feb 24, 2025 | The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a ... |
| CVE-2025-27355 | HIGH | 7.1 | 0.1% | Feb 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Nicolas GRILLET Woocommerce – Loi Hamon loi-hamon allows Stored XSS.T... |
| CVE-2025-27352 | HIGH | 7.1 | 0.2% | Feb 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wumii team 无觅相关文章插... |
| CVE-2025-27332 | HIGH | 7.1 | 0.1% | Feb 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in gmnazmul Smart Maintenance & Countdown smart-maintenance-countdown al... |
| CVE-2025-27321 | HIGH | 7.1 | 0.1% | Feb 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Blighty Blightly Explorer blighty-explorer allows Stored XSS.This iss... |
| CVE-2025-27312 | HIGH | 8.5 | 0.3% | Feb 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jenst WP Sitemap w... |
| CVE-2025-27301 | HIGH | 7.2 | 0.6% | Feb 24, 2025 | Deserialization of Untrusted Data vulnerability in Nazmul Hasan Robin NHR Options Table Manager nhrrob-options-table-man... |
| CVE-2025-27300 | HIGH | 7.2 | 0.6% | Feb 24, 2025 | Deserialization of Untrusted Data vulnerability in giuliopanda ADFO admin-form allows Object Injection.This issue affect... |
| CVE-2025-27298 | HIGH | 8.3 | 0.3% | Feb 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in cmstactics WP Video Posts wp-video-posts allows OS Command Injection.... |
| CVE-2025-27297 | HIGH | 7.6 | 0.4% | Feb 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in guelben Bravo Sear... |
| CVE-2025-27296 | HIGH | 7.2 | 0.5% | Feb 24, 2025 | Missing Authorization vulnerability in revenueflex Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue rev... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now