2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69267 | MEDIUM | 6.5 | 0.3% | Jan 12, 2026 | Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectru... |
| CVE-2025-13393 | MEDIUM | 4.3 | 0.2% | Jan 10, 2026 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up ... |
| CVE-2025-12379 | MEDIUM | 6.4 | 0.2% | Jan 10, 2026 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2025-14555 | MEDIUM | 6.4 | 0.2% | Jan 10, 2026 | The Countdown Timer – Widget Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'... |
| CVE-2025-15504 | MEDIUM | 5.5 | 0.2% | Jan 10, 2026 | A security flaw has been discovered in lief-project LIEF up to 0.17.1. Affected by this issue is the function Parser::pa... |
| CVE-2025-14506 | MEDIUM | 6.4 | 0.2% | Jan 10, 2026 | The ConvertForce Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gutenberg block... |
| CVE-2025-14976 | MEDIUM | 5.4 | 0.1% | Jan 10, 2026 | The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restrict... |
| CVE-2025-14948 | MEDIUM | 5.3 | 0.2% | Jan 10, 2026 | The miniOrange OTP Verification and SMS Notification for WooCommerce plugin for WordPress is vulnerable to unauthorized ... |
| CVE-2025-14943 | MEDIUM | 4.3 | 0.2% | Jan 10, 2026 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure... |
| CVE-2025-65090 | MEDIUM | 5.3 | 0.2% | Jan 10, 2026 | XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights ... |
| CVE-2025-61676 | MEDIUM | 4.8 | 0.2% | Jan 10, 2026 | October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripti... |
| CVE-2025-61674 | MEDIUM | 4.8 | 0.2% | Jan 10, 2026 | October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripti... |
| CVE-2025-68470 | MEDIUM | 6.5 | 0.2% | Jan 10, 2026 | React Router is a router for React. In versions 6.0.0 through 6.30.1 and 7.0.0 through 7.9.5, an attacker-supplied path ... |
| CVE-2025-46299 | MEDIUM | 4.3 | 0.3% | Jan 9, 2026 | A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 ... |
| CVE-2025-46298 | MEDIUM | 6.5 | 0.3% | Jan 9, 2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, mac... |
| CVE-2025-46297 | MEDIUM | 5.5 | 0.1% | Jan 9, 2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.2. An app may be a... |
| CVE-2025-46286 | MEDIUM | 4.3 | 0.2% | Jan 9, 2026 | A logic issue was addressed with improved validation. This issue is fixed in iOS 26.2 and iPadOS 26.2. Restoring from a ... |
| CVE-2025-60538 | MEDIUM | 6.5 | 0.4% | Jan 9, 2026 | A lack of rate limiting in the login page of shiori v1.7.4 and below allows attackers to bypass authentication via a bru... |
| CVE-2025-51626 | MEDIUM | 6.5 | 0.2% | Jan 9, 2026 | SQL injection vulnerability in pss.sale.com 1.0 via the id parameter to the userfiles/php/cancel_order.php endpoint. |
| CVE-2025-67811 | MEDIUM | 6.5 | 0.3% | Jan 9, 2026 | Area9 Rhapsode 1.47.3 allows SQL Injection via multiple API endpoints accessible to authenticated users. Insufficient in... |
| CVE-2025-67810 | MEDIUM | 6.5 | 0.3% | Jan 9, 2026 | In Area9 Rhapsode 1.47.3, an authenticated attacker can exploit the operation, url, and filename parameters via POST req... |
| CVE-2025-66715 | MEDIUM | 6.5 | 0.2% | Jan 9, 2026 | A DLL hijacking vulnerability in Axtion ODISSAAS ODIS v1.8.4 allows attackers to execute arbitrary code via a crafted DL... |
| CVE-2025-67004 | MEDIUM | 6.5 | 5.6% | Jan 9, 2026 | ** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via t... |
| CVE-2025-67282 | MEDIUM | 5.4 | 0.2% | Jan 9, 2026 | In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileg... |
| CVE-2025-67281 | MEDIUM | 5.4 | 0.2% | Jan 9, 2026 | In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple SQL injection vulnerabilities exists which allow a low privileged and ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now