2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-56451 | MEDIUM | 6.1 | 0.2% | Jan 16, 2026 | Cross site scripting vulnerability in seeyon Zhiyuan A8+ Collaborative Management Software 7.0 via the topValue paramete... |
| CVE-2025-69581 | MEDIUM | 5.5 | 0.2% | Jan 16, 2026 | An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user i... |
| CVE-2025-51602 | MEDIUM | 4.8 | 0.4% | Jan 16, 2026 | mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01... |
| CVE-2025-43904 | MEDIUM | 4.2 | 0.2% | Jan 16, 2026 | In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user ... |
| CVE-2025-43508 | MEDIUM | 5.5 | 0.1% | Jan 16, 2026 | A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able ... |
| CVE-2025-24531 | MEDIUM | 6.7 | 0.2% | Jan 16, 2026 | In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as a... |
| CVE-2025-24089 | MEDIUM | 5.3 | 0.3% | Jan 16, 2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app ... |
| CVE-2025-29943 | MEDIUM | 4.6 | 0.2% | Jan 16, 2026 | Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU ... |
| CVE-2025-15104 | MEDIUM | 5.3 | 0.4% | Jan 16, 2026 | Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arb... |
| CVE-2025-14435 | MEDIUM | 6.5 | 0.3% | Jan 16, 2026 | Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite re-renders on API er... |
| CVE-2025-14822 | MEDIUM | 6.5 | 0.3% | Jan 16, 2026 | Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authentica... |
| CVE-2025-14757 | MEDIUM | 5.3 | 0.3% | Jan 16, 2026 | The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Payment Status Bypass in all versions ... |
| CVE-2025-14375 | MEDIUM | 6.1 | 0.2% | Jan 16, 2026 | The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Reflec... |
| CVE-2025-14853 | MEDIUM | 4.3 | 0.1% | Jan 16, 2026 | The LEAV Last Email Address Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions <= 1.... |
| CVE-2025-14793 | MEDIUM | 5 | 0.2% | Jan 16, 2026 | The DK PDF – WordPress PDF Generator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions u... |
| CVE-2025-15527 | MEDIUM | 4.3 | 0.3% | Jan 16, 2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 10.2.2 ... |
| CVE-2025-15526 | MEDIUM | 5.3 | 0.3% | Jan 16, 2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and includi... |
| CVE-2025-15370 | MEDIUM | 4.3 | 0.2% | Jan 16, 2026 | The Shield: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to Insecure D... |
| CVE-2025-14982 | MEDIUM | 4.3 | 0.3% | Jan 16, 2026 | The Booking Calendar plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Exposu... |
| CVE-2025-14384 | MEDIUM | 4.3 | 0.2% | Jan 16, 2026 | The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to ... |
| CVE-2025-12641 | MEDIUM | 6.5 | 0.4% | Jan 16, 2026 | The Awesome Support - WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to mis... |
| CVE-2025-68671 | MEDIUM | 4.8 | 0.2% | Jan 15, 2026 | lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not ... |
| CVE-2025-70891 | MEDIUM | 6.1 | 0.2% | Jan 15, 2026 | A stored cross-site scripting (XSS) vulnerability exists in Phpgurukul Cyber Cafe Management System v1.0 within the user... |
| CVE-2025-70890 | MEDIUM | 6.1 | 0.2% | Jan 15, 2026 | A stored cross-site scripting (XSS) vulnerability exists in Cyber Cafe Management System v1.0. An authenticated attacker... |
| CVE-2025-67025 | MEDIUM | 6.1 | 0.3% | Jan 15, 2026 | Cross Site Scripting vulnerability in Anycomment anycomment.io 0.4.4 allows a remote attacker to execute arbitrary code ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now