2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0236 | MEDIUM | 5.3 | 0.6% | Feb 26, 2025 | Out-of-bounds vulnerability in slope processing during curve rendering in Generic PCL6 V4 Printer Driver / Generic UFR I... |
| CVE-2025-0235 | MEDIUM | 5.3 | 0.6% | Feb 26, 2025 | Out-of-bounds vulnerability due to improper memory release during image rendering in Generic PCL6 V4 Printer Driver / Ge... |
| CVE-2025-0234 | MEDIUM | 5.3 | 0.6% | Feb 26, 2025 | Out-of-bounds vulnerability in curve segmentation processing of Generic PCL6 V4 Printer Driver / Generic UFR II V4 Print... |
| CVE-2025-1091 | MEDIUM | 4.3 | 0.2% | Feb 26, 2025 | A Broken Authorization schema exists where any authenticated user could download IOA script and configuration files if t... |
| CVE-2025-25514 | MEDIUM | 6.5 | 0.3% | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php. |
| CVE-2025-27146 | MEDIUM | 4.3 | 0.3% | Feb 25, 2025 | matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains ... |
| CVE-2025-27139 | MEDIUM | 5.4 | 0.2% | Feb 25, 2025 | Combodo iTop is a web based IT service management tool. Versions prior to 2.7.12, 3.1.2, and 3.2.0 are vulnerable to cro... |
| CVE-2025-25192 | MEDIUM | 6.5 | 0.6% | Feb 25, 2025 | GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged user can enable debu... |
| CVE-2025-23024 | MEDIUM | 4.3 | 0.3% | Feb 25, 2025 | GLPI is a free asset and IT management software package. Starting in version 0.72 and prior to version 10.0.18, an anony... |
| CVE-2025-21627 | MEDIUM | 6.1 | 0.3% | Feb 25, 2025 | GLPI is a free asset and IT management software package. In versions prior to 10.0.18, a malicious link can be crafted t... |
| CVE-2025-21626 | MEDIUM | 6.5 | 0.4% | Feb 25, 2025 | GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anony... |
| CVE-2025-27000 | MEDIUM | 5.4 | 0.3% | Feb 25, 2025 | Missing Authorization vulnerability in George Pattichis Simple Photo Feed simple-photo-feed allows Exploiting Incorrectl... |
| CVE-2025-26995 | MEDIUM | 5.4 | 0.3% | Feb 25, 2025 | Missing Authorization vulnerability in Anton Vanyukov Market Exporter market-exporter allows Exploiting Incorrectly Conf... |
| CVE-2025-26987 | MEDIUM | 6.1 | 0.3% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shabti Kaplan Fron... |
| CVE-2025-26983 | MEDIUM | 4.3 | 0.3% | Feb 25, 2025 | Missing Authorization vulnerability in WPZOOM Recipe Card Blocks for Gutenberg & Elementor recipe-card-blocks-by-wpzoom ... |
| CVE-2025-26980 | MEDIUM | 6.5 | 0.3% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wired Impact Wired... |
| CVE-2025-26975 | MEDIUM | 5.3 | 0.4% | Feb 25, 2025 | Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Accessing Functionality N... |
| CVE-2025-26965 | MEDIUM | 5.3 | 0.4% | Feb 25, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in ameliabooking Amelia ameliabooking allows Exploiting I... |
| CVE-2025-26962 | MEDIUM | 6.5 | 0.2% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Easy Cont... |
| CVE-2025-26960 | MEDIUM | 6.5 | 0.4% | Feb 25, 2025 | Missing Authorization vulnerability in enituretechnology Small Package Quotes – Unishippers Edition small-package-quotes... |
| CVE-2025-26952 | MEDIUM | 6.5 | 0.2% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Business ... |
| CVE-2025-26949 | MEDIUM | 6.5 | 0.2% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Team Sect... |
| CVE-2025-26948 | MEDIUM | 4.3 | 0.3% | Feb 25, 2025 | Missing Authorization vulnerability in NotFound Pie Register Premium. This issue affects Pie Register Premium: from n/a ... |
| CVE-2025-26947 | MEDIUM | 6.5 | 0.2% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Services ... |
| CVE-2025-26945 | MEDIUM | 6.5 | 0.2% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Info Card... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now