2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13725 | MEDIUM | 6.5 | 0.4% | Jan 17, 2026 | The Gutenberg Thim Blocks – Page Builder, Gutenberg Blocks for the Block Editor plugin for WordPress is vulnerable to ar... |
| CVE-2025-14632 | MEDIUM | 4.4 | 0.2% | Jan 17, 2026 | The Filr – Secure document library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via unrestricted fi... |
| CVE-2025-14450 | MEDIUM | 6.5 | 0.2% | Jan 17, 2026 | The Wallet System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2025-14075 | MEDIUM | 5.3 | 0.3% | Jan 17, 2026 | The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc... |
| CVE-2025-12718 | MEDIUM | 5.8 | 0.2% | Jan 17, 2026 | The Quick Contact Form plugin for WordPress is vulnerable to Open Mail Relay in all versions up to, and including, 8.2.6... |
| CVE-2025-12002 | MEDIUM | 5.9 | 0.4% | Jan 17, 2026 | The Feeds for YouTube Pro plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including... |
| CVE-2025-56451 | MEDIUM | 6.1 | 0.2% | Jan 16, 2026 | Cross site scripting vulnerability in seeyon Zhiyuan A8+ Collaborative Management Software 7.0 via the topValue paramete... |
| CVE-2025-69581 | MEDIUM | 5.5 | 0.2% | Jan 16, 2026 | An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user i... |
| CVE-2025-51602 | MEDIUM | 4.8 | 0.4% | Jan 16, 2026 | mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01... |
| CVE-2025-43904 | MEDIUM | 4.2 | 0.2% | Jan 16, 2026 | In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user ... |
| CVE-2025-43508 | MEDIUM | 5.5 | 0.1% | Jan 16, 2026 | A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able ... |
| CVE-2025-24531 | MEDIUM | 6.7 | 0.2% | Jan 16, 2026 | In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as a... |
| CVE-2025-24089 | MEDIUM | 5.3 | 0.3% | Jan 16, 2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app ... |
| CVE-2025-29943 | MEDIUM | 4.6 | 0.2% | Jan 16, 2026 | Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU ... |
| CVE-2025-15104 | MEDIUM | 5.3 | 0.4% | Jan 16, 2026 | Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arb... |
| CVE-2025-14435 | MEDIUM | 6.5 | 0.3% | Jan 16, 2026 | Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite re-renders on API er... |
| CVE-2025-14822 | MEDIUM | 6.5 | 0.3% | Jan 16, 2026 | Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authentica... |
| CVE-2025-14757 | MEDIUM | 5.3 | 0.3% | Jan 16, 2026 | The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Payment Status Bypass in all versions ... |
| CVE-2025-14375 | MEDIUM | 6.1 | 0.2% | Jan 16, 2026 | The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Reflec... |
| CVE-2025-14853 | MEDIUM | 4.3 | 0.1% | Jan 16, 2026 | The LEAV Last Email Address Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions <= 1.... |
| CVE-2025-14793 | MEDIUM | 5 | 0.2% | Jan 16, 2026 | The DK PDF – WordPress PDF Generator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions u... |
| CVE-2025-15527 | MEDIUM | 4.3 | 0.3% | Jan 16, 2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 10.2.2 ... |
| CVE-2025-15526 | MEDIUM | 5.3 | 0.3% | Jan 16, 2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and includi... |
| CVE-2025-15370 | MEDIUM | 4.3 | 0.2% | Jan 16, 2026 | The Shield: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to Insecure D... |
| CVE-2025-14982 | MEDIUM | 4.3 | 0.3% | Jan 16, 2026 | The Booking Calendar plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Exposu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now