2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14379 | MEDIUM | 4.4 | 0.2% | Jan 14, 2026 | The Testimonials Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version... |
| CVE-2025-13627 | MEDIUM | 4.4 | 0.2% | Jan 14, 2026 | The Makesweat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'makesweat_clubid' setting in al... |
| CVE-2025-12178 | MEDIUM | 6.4 | 0.2% | Jan 14, 2026 | The SpiceForms Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'spiceforms' short... |
| CVE-2025-68970 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulner... |
| CVE-2025-68969 | MEDIUM | 4.7 | 0.1% | Jan 14, 2026 | Multi-thread race condition vulnerability in the thermal management module. Impact: Successful exploitation of this vuln... |
| CVE-2025-68967 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability ... |
| CVE-2025-68966 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect... |
| CVE-2025-68965 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect... |
| CVE-2025-68964 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | Data verification vulnerability in the HiView module. Impact: Successful exploitation of this vulnerability may affect a... |
| CVE-2025-68963 | MEDIUM | 5.3 | 0.1% | Jan 14, 2026 | Man-in-the-middle attack vulnerability in the Clone module. Impact: Successful exploitation of this vulnerability may af... |
| CVE-2025-68962 | MEDIUM | 4.7 | 0.1% | Jan 14, 2026 | Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulner... |
| CVE-2025-68961 | MEDIUM | 4.7 | 0.1% | Jan 14, 2026 | Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulner... |
| CVE-2025-68960 | MEDIUM | 4.7 | 0.1% | Jan 14, 2026 | Multi-thread race condition vulnerability in the video framework module. Impact: Successful exploitation of this vulnera... |
| CVE-2025-68959 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulner... |
| CVE-2025-68958 | MEDIUM | 4.7 | 0.1% | Jan 14, 2026 | Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerab... |
| CVE-2025-68957 | MEDIUM | 4.7 | 0.1% | Jan 14, 2026 | Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerab... |
| CVE-2025-68956 | MEDIUM | 4.7 | 0.1% | Jan 14, 2026 | Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerab... |
| CVE-2025-68955 | MEDIUM | 4.7 | 0.1% | Jan 14, 2026 | Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnera... |
| CVE-2025-68947 | MEDIUM | 5.7 | 0.1% | Jan 13, 2026 | NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by othe... |
| CVE-2025-68658 | MEDIUM | 4.8 | 0.2% | Jan 13, 2026 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram... |
| CVE-2025-15056 | MEDIUM | 6.1 | 0.2% | Jan 13, 2026 | A lack of data validation vulnerability in the HTML export feature in Quill in allows Cross-Site Scripting (XSS). This ... |
| CVE-2025-68925 | MEDIUM | 5.3 | 0.1% | Jan 13, 2026 | Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the code doesn't val... |
| CVE-2025-37179 | MEDIUM | 5.3 | 0.3% | Jan 13, 2026 | Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data ... |
| CVE-2025-37177 | MEDIUM | 6.5 | 0.3% | Jan 13, 2026 | An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors runnin... |
| CVE-2025-68949 | MEDIUM | 5.3 | 0.3% | Jan 13, 2026 | n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validat... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now