2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26306 | MEDIUM | 6.5 | 0.4% | Feb 20, 2025 | A memory leak has been identified in the readSizedString function in util/read.c of libming v0.4.8, which allows attacke... |
| CVE-2025-1039 | MEDIUM | 6.1 | 0.4% | Feb 20, 2025 | The Lenix Elementor Leads addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a URL form field i... |
| CVE-2025-21106 | MEDIUM | 5.5 | 0.1% | Feb 20, 2025 | Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Loc... |
| CVE-2025-1043 | MEDIUM | 6.4 | 0.3% | Feb 20, 2025 | The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Server-Side R... |
| CVE-2025-1483 | MEDIUM | 5.3 | 0.3% | Feb 20, 2025 | The LTL Freight Quotes – GlobalTranz Edition plugin for WordPress is vulnerable to unauthorized modification of data due... |
| CVE-2025-1328 | MEDIUM | 5.4 | 0.3% | Feb 20, 2025 | The Typed JS: A typewriter style animation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ty... |
| CVE-2025-0866 | MEDIUM | 6.5 | 0.4% | Feb 20, 2025 | The Legoeso PDF Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘checkedVals’ parameter i... |
| CVE-2025-1064 | MEDIUM | 5.4 | 0.3% | Feb 20, 2025 | The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2025-0897 | MEDIUM | 5.4 | 0.3% | Feb 20, 2025 | The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p... |
| CVE-2025-27218 | MEDIUM | 5.3 | 63.6% | Feb 20, 2025 | Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through ... |
| CVE-2025-24947 | MEDIUM | 5.3 | 0.6% | Feb 20, 2025 | A hash collision vulnerability (in the hash table used to manage connections) in LSQUIC (aka LiteSpeed QUIC) before 4.2.... |
| CVE-2025-24946 | MEDIUM | 5.3 | 0.5% | Feb 20, 2025 | The hash table used to manage connections in picoquic before b80fd3f uses a weak hash function, allowing remote attacker... |
| CVE-2025-23020 | MEDIUM | 5.3 | 0.5% | Feb 20, 2025 | An issue was discovered in Kwik before 0.10.1. A hash collision vulnerability (in the hash table used to manage connecti... |
| CVE-2025-1223 | MEDIUM | 6.1 | 0.2% | Feb 20, 2025 | An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citri... |
| CVE-2025-1222 | MEDIUM | 6.1 | 0.2% | Feb 20, 2025 | An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citri... |
| CVE-2025-0112 | MEDIUM | 6.8 | 0.2% | Feb 20, 2025 | A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with W... |
| CVE-2025-25947 | MEDIUM | 5.5 | 0.2% | Feb 19, 2025 | An issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in AP4_At... |
| CVE-2025-25946 | MEDIUM | 5.5 | 0.2% | Feb 19, 2025 | An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specific... |
| CVE-2025-25945 | MEDIUM | 6.5 | 0.4% | Feb 19, 2025 | An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in AP4_... |
| CVE-2025-25942 | MEDIUM | 6.5 | 0.4% | Feb 19, 2025 | An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when proce... |
| CVE-2025-27090 | MEDIUM | 5.3 | 0.6% | Feb 19, 2025 | Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all s... |
| CVE-2025-0677 | MEDIUM | 6.4 | 0.3% | Feb 19, 2025 | A flaw was found in grub2. When performing a symlink lookup, the grub's UFS module checks the inode's data size to alloc... |
| CVE-2025-1118 | MEDIUM | 4.4 | 0.3% | Feb 19, 2025 | A flaw was found in grub2. Grub's dump command is not blocked when grub is in lockdown mode, which allows the user to re... |
| CVE-2025-27089 | MEDIUM | 4.3 | 0.2% | Feb 19, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. In affected versions if there are two o... |
| CVE-2025-20211 | MEDIUM | 6.1 | 0.3% | Feb 19, 2025 | A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform could allow an u... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now