2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27144 | MEDIUM | 6.6 | 0.4% | Feb 24, 2025 | Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including sup... |
| CVE-2025-27143 | MEDIUM | 6.1 | 0.3% | Feb 24, 2025 | Better Auth is an authentication and authorization library for TypeScript. Prior to version 1.1.21, the application is v... |
| CVE-2025-27141 | MEDIUM | 6.5 | 0.3% | Feb 24, 2025 | Metabase Enterprise Edition is the enterprise version of Metabase business intelligence and data analytics software. Sta... |
| CVE-2025-27137 | MEDIUM | 4.4 | 0.2% | Feb 24, 2025 | Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software ... |
| CVE-2025-26532 | MEDIUM | 4.3 | 0.2% | Feb 24, 2025 | Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored. |
| CVE-2025-26531 | MEDIUM | 5.3 | 0.3% | Feb 24, 2025 | Insufficient capability checks made it possible to disable badges a user does not have permission to access. |
| CVE-2025-26530 | MEDIUM | 6.1 | 0.3% | Feb 24, 2025 | The question bank filter required additional sanitizing to prevent a reflected XSS risk. |
| CVE-2025-26529 | MEDIUM | 6.1 | 0.5% | Feb 24, 2025 | Description information displayed in the site administration live log required additional sanitizing to prevent a store... |
| CVE-2025-26528 | MEDIUM | 6.1 | 0.3% | Feb 24, 2025 | The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk. |
| CVE-2025-26527 | MEDIUM | 5.3 | 0.3% | Feb 24, 2025 | Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block... |
| CVE-2025-26526 | MEDIUM | 6.5 | 0.3% | Feb 24, 2025 | Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of respo... |
| CVE-2025-27112 | MEDIUM | 6.5 | 0.9% | Feb 24, 2025 | Navidrome is an open source web-based music collection server and streamer. Starting in version 0.52.0 and prior to vers... |
| CVE-2025-25460 | MEDIUM | 4.8 | 0.5% | Feb 24, 2025 | A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This... |
| CVE-2025-27357 | MEDIUM | 4.3 | 0.1% | Feb 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Musa AVCI Önceki Yazı Link onceki-yazi-linki allows Cross Site Reques... |
| CVE-2025-27356 | MEDIUM | 5.4 | 0.3% | Feb 24, 2025 | Missing Authorization vulnerability in Hardik Sticky Header On Scroll sticky-header-on-scroll allows Exploiting Incorrec... |
| CVE-2025-27353 | MEDIUM | 4.3 | 0.1% | Feb 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Bob Namaste! LMS namaste-lms allows Cross Site Request Forgery.This i... |
| CVE-2025-27351 | MEDIUM | 6.5 | 0.2% | Feb 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpertBusinessSear... |
| CVE-2025-27349 | MEDIUM | 6.5 | 0.2% | Feb 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nurelm Get Posts n... |
| CVE-2025-27348 | MEDIUM | 6.5 | 0.2% | Feb 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel WP Social S... |
| CVE-2025-27347 | MEDIUM | 6.5 | 0.2% | Feb 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in techmix Direct Che... |
| CVE-2025-27344 | MEDIUM | 4.3 | 0.1% | Feb 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in filipstepanov Phee's LinkPreview linkpreview allows Cross Site Reques... |
| CVE-2025-27342 | MEDIUM | 4.3 | 0.1% | Feb 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in josesan WooCommerce Recargo de Equivalencia woo-recargo-de-equivalenc... |
| CVE-2025-27341 | MEDIUM | 6.5 | 0.2% | Feb 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in afzal_du Reactive ... |
| CVE-2025-27340 | MEDIUM | 5.4 | 0.1% | Feb 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Forge12 Interactive GmbH F12-Profiler f12-profiler allows Cross Site ... |
| CVE-2025-27339 | MEDIUM | 4.3 | 0.1% | Feb 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Will Anderson Minimum Password Strength minimum-password-strength all... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now