2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65368 | MEDIUM | 6.1 | 0.2% | Jan 15, 2026 | SparkyFitness v0.15.8.2 is vulnerable to Cross Site Scripting (XSS) via user input and LLM output. |
| CVE-2025-60011 | MEDIUM | 6.9 | 0.4% | Jan 15, 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Ne... |
| CVE-2025-60007 | MEDIUM | 6.8 | 0.1% | Jan 15, 2026 | A NULL Pointer Dereference vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS on MX, SRX and EX... |
| CVE-2025-59961 | MEDIUM | 6.8 | 0.1% | Jan 15, 2026 | An Incorrect Permission Assignment for Critical Resource vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Ne... |
| CVE-2025-59959 | MEDIUM | 6.8 | 0.1% | Jan 15, 2026 | An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Jun... |
| CVE-2025-52987 | MEDIUM | 6.1 | 0.2% | Jan 15, 2026 | A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insig... |
| CVE-2025-65349 | MEDIUM | 5.4 | 0.2% | Jan 15, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability in Web management interface in Each Italy Wireless Mini Router WIRELES... |
| CVE-2025-15265 | MEDIUM | 6.1 | 0.3% | Jan 15, 2026 | An SSR XSS exists in async hydration when attacker‑controlled keys are passed to hydratable. The key is embedded inside ... |
| CVE-2025-70303 | MEDIUM | 5.5 | 0.2% | Jan 15, 2026 | A heap overflow in the uncv_parse_config() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) v... |
| CVE-2025-70302 | MEDIUM | 5.5 | 0.2% | Jan 15, 2026 | A heap overflow in the ghi_dmx_declare_opid_bin() function of GPAC v2.4.0 allows attackers to cause a Denial of Service ... |
| CVE-2025-13844 | MEDIUM | 5.3 | 0.1% | Jan 15, 2026 | CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious ... |
| CVE-2025-70299 | MEDIUM | 6.5 | 0.3% | Jan 15, 2026 | A heap overflow in the avi_parse_input_file() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS... |
| CVE-2025-70310 | MEDIUM | 5.5 | 0.1% | Jan 15, 2026 | A heap overflow in the vorbis_to_intern() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) vi... |
| CVE-2025-70309 | MEDIUM | 5.5 | 0.1% | Jan 15, 2026 | A stack overflow in the pcmreframe_flush_packet function of GPAC v2.4.0 allows attackers to cause a Denial of Service (D... |
| CVE-2025-70305 | MEDIUM | 5.5 | 0.2% | Jan 15, 2026 | A stack overflow in the dmx_saf function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafte... |
| CVE-2025-67078 | MEDIUM | 6.1 | 0.2% | Jan 15, 2026 | Cross site scripting (XSS) vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute arbitrary... |
| CVE-2025-67083 | MEDIUM | 5.3 | 0.6% | Jan 15, 2026 | Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the ... |
| CVE-2025-67082 | MEDIUM | 6.5 | 0.3% | Jan 15, 2026 | An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" para... |
| CVE-2025-67081 | MEDIUM | 4.9 | 0.2% | Jan 15, 2026 | An SQL injection vulnerability in Itflow through 25.06 has been identified in the "role_id" parameter when editing a pro... |
| CVE-2025-13859 | MEDIUM | 6.4 | 0.2% | Jan 15, 2026 | The AffiliateX – Amazon Affiliate Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to ... |
| CVE-2025-12895 | MEDIUM | 5.3 | 0.2% | Jan 15, 2026 | The Kalium 3 | Creative WordPress & WooCommerce Theme theme for WordPress is vulnerable to unauthorized email sending du... |
| CVE-2025-14448 | MEDIUM | 5.4 | 0.2% | Jan 15, 2026 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Multiple Chec... |
| CVE-2025-13454 | MEDIUM | 6.8 | 0.1% | Jan 14, 2026 | A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user t... |
| CVE-2025-13453 | MEDIUM | 5.1 | 0.1% | Jan 14, 2026 | A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read... |
| CVE-2025-13154 | MEDIUM | 6.8 | 0.1% | Jan 14, 2026 | An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now