2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14384 | MEDIUM | 4.3 | 0.2% | Jan 16, 2026 | The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to ... |
| CVE-2025-12641 | MEDIUM | 6.5 | 0.4% | Jan 16, 2026 | The Awesome Support - WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to mis... |
| CVE-2025-68671 | MEDIUM | 4.8 | 0.2% | Jan 15, 2026 | lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not ... |
| CVE-2025-70891 | MEDIUM | 6.1 | 0.2% | Jan 15, 2026 | A stored cross-site scripting (XSS) vulnerability exists in Phpgurukul Cyber Cafe Management System v1.0 within the user... |
| CVE-2025-70890 | MEDIUM | 6.1 | 0.2% | Jan 15, 2026 | A stored cross-site scripting (XSS) vulnerability exists in Cyber Cafe Management System v1.0. An authenticated attacker... |
| CVE-2025-67025 | MEDIUM | 6.1 | 0.3% | Jan 15, 2026 | Cross Site Scripting vulnerability in Anycomment anycomment.io 0.4.4 allows a remote attacker to execute arbitrary code ... |
| CVE-2025-65368 | MEDIUM | 6.1 | 0.2% | Jan 15, 2026 | SparkyFitness v0.15.8.2 is vulnerable to Cross Site Scripting (XSS) via user input and LLM output. |
| CVE-2025-60011 | MEDIUM | 6.9 | 0.4% | Jan 15, 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Ne... |
| CVE-2025-60007 | MEDIUM | 6.8 | 0.1% | Jan 15, 2026 | A NULL Pointer Dereference vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS on MX, SRX and EX... |
| CVE-2025-59961 | MEDIUM | 6.8 | 0.1% | Jan 15, 2026 | An Incorrect Permission Assignment for Critical Resource vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Ne... |
| CVE-2025-59959 | MEDIUM | 6.8 | 0.1% | Jan 15, 2026 | An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Jun... |
| CVE-2025-52987 | MEDIUM | 6.1 | 0.2% | Jan 15, 2026 | A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insig... |
| CVE-2025-65349 | MEDIUM | 5.4 | 0.2% | Jan 15, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability in Web management interface in Each Italy Wireless Mini Router WIRELES... |
| CVE-2025-15265 | MEDIUM | 6.1 | 0.3% | Jan 15, 2026 | An SSR XSS exists in async hydration when attacker‑controlled keys are passed to hydratable. The key is embedded inside ... |
| CVE-2025-70303 | MEDIUM | 5.5 | 0.2% | Jan 15, 2026 | A heap overflow in the uncv_parse_config() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) v... |
| CVE-2025-70302 | MEDIUM | 5.5 | 0.2% | Jan 15, 2026 | A heap overflow in the ghi_dmx_declare_opid_bin() function of GPAC v2.4.0 allows attackers to cause a Denial of Service ... |
| CVE-2025-13844 | MEDIUM | 5.3 | 0.1% | Jan 15, 2026 | CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious ... |
| CVE-2025-70299 | MEDIUM | 6.5 | 0.3% | Jan 15, 2026 | A heap overflow in the avi_parse_input_file() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS... |
| CVE-2025-70310 | MEDIUM | 5.5 | 0.1% | Jan 15, 2026 | A heap overflow in the vorbis_to_intern() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) vi... |
| CVE-2025-70309 | MEDIUM | 5.5 | 0.1% | Jan 15, 2026 | A stack overflow in the pcmreframe_flush_packet function of GPAC v2.4.0 allows attackers to cause a Denial of Service (D... |
| CVE-2025-70305 | MEDIUM | 5.5 | 0.2% | Jan 15, 2026 | A stack overflow in the dmx_saf function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafte... |
| CVE-2025-67078 | MEDIUM | 6.1 | 0.2% | Jan 15, 2026 | Cross site scripting (XSS) vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute arbitrary... |
| CVE-2025-67083 | MEDIUM | 5.3 | 0.6% | Jan 15, 2026 | Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the ... |
| CVE-2025-67082 | MEDIUM | 6.5 | 0.3% | Jan 15, 2026 | An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" para... |
| CVE-2025-67081 | MEDIUM | 4.9 | 0.2% | Jan 15, 2026 | An SQL injection vulnerability in Itflow through 25.06 has been identified in the "role_id" parameter when editing a pro... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now