2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20158 | MEDIUM | 4.4 | 0.1% | Feb 19, 2025 | A vulnerability in the debug shell of Cisco Video Phone 8875 and Cisco Desk Phone 9800 Series could allow an authenticat... |
| CVE-2025-20153 | MEDIUM | 5.3 | 0.3% | Feb 19, 2025 | A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote at... |
| CVE-2025-1465 | MEDIUM | 6.6 | 0.5% | Feb 19, 2025 | A vulnerability, which was classified as problematic, was found in lmxcms 1.41. Affected is an unknown function of the f... |
| CVE-2025-0968 | MEDIUM | 5.3 | 0.5% | Feb 19, 2025 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up... |
| CVE-2025-0916 | MEDIUM | 6.1 | 0.4% | Feb 19, 2025 | The YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service plugin for WordPr... |
| CVE-2025-1024 | MEDIUM | 4.8 | 0.3% | Feb 19, 2025 | A vulnerability exists in ChurchCRM 5.13.0 that allows an attacker to execute arbitrary JavaScript in a victim's browser... |
| CVE-2025-1007 | MEDIUM | 5.3 | 0.5% | Feb 19, 2025 | In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace ... |
| CVE-2025-0865 | MEDIUM | 6.5 | 0.3% | Feb 19, 2025 | The WP Media Category Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.0 to 2.3... |
| CVE-2025-0633 | MEDIUM | 5.1 | 0.2% | Feb 19, 2025 | Heap-based Buffer Overflow vulnerability in iniparser_dumpsection_ini() in iniparser allows attacker to read out of boun... |
| CVE-2025-25054 | MEDIUM | 6.1 | 0.2% | Feb 19, 2025 | Movable Type contains a reflected cross-site scripting vulnerability in the user information edit page. When Multi-Facto... |
| CVE-2025-24841 | MEDIUM | 5.4 | 0.2% | Feb 19, 2025 | Movable Type contains a stored cross-site scripting vulnerability in the HTML edit mode of MT Block Editor. It is exploi... |
| CVE-2025-22888 | MEDIUM | 5.4 | 0.2% | Feb 19, 2025 | Movable Type contains a stored cross-site scripting vulnerability in the custom block edit page of MT Block Editor. If e... |
| CVE-2025-1065 | MEDIUM | 6.4 | 0.3% | Feb 19, 2025 | The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2025-22622 | MEDIUM | 4.3 | 0.3% | Feb 19, 2025 | Age Verification for your checkout page. Verify your customer's identity 1.20.0 was found to be vulnerable. The web appl... |
| CVE-2025-1447 | MEDIUM | 5.3 | 0.3% | Feb 19, 2025 | A vulnerability was found in kasuganosoras Pigeon 1.0.177. It has been declared as critical. This vulnerability affects ... |
| CVE-2025-26624 | MEDIUM | 6.8 | 0.2% | Feb 18, 2025 | Rufus is a utility that helps format and create bootable USB flash drives. A DLL hijacking vulnerability in Rufus 4.6.22... |
| CVE-2025-25474 | MEDIUM | 6.5 | 0.3% | Feb 18, 2025 | DCMTK v3.6.9+ DEV was discovered to contain a buffer overflow via the component /dcmimgle/diinpxt.h. |
| CVE-2025-25473 | MEDIUM | 5.3 | 0.4% | Feb 18, 2025 | FFmpeg git master before commit c08d30 was discovered to contain a memory leak in the avformat_free_context function in ... |
| CVE-2025-25472 | MEDIUM | 5.3 | 0.3% | Feb 18, 2025 | A buffer overflow in DCMTK git master v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DCM ... |
| CVE-2025-25471 | MEDIUM | 4.3 | 0.3% | Feb 18, 2025 | FFmpeg git master before commit fd1772 was discovered to contain a NULL pointer dereference via the component libavforma... |
| CVE-2025-22920 | MEDIUM | 5.3 | 0.3% | Feb 18, 2025 | A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via... |
| CVE-2025-22919 | MEDIUM | 6.5 | 0.4% | Feb 18, 2025 | A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (Do... |
| CVE-2025-25896 | MEDIUM | 5.7 | 0.5% | Feb 18, 2025 | A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01 via the destination, netmask, and gateway parame... |
| CVE-2025-25892 | MEDIUM | 5.7 | 0.3% | Feb 18, 2025 | A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01 via the sstartip, sendip, dstartip, and dendip p... |
| CVE-2025-25891 | MEDIUM | 5.7 | 0.3% | Feb 18, 2025 | A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01, triggered by the destination, netmask and gatew... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now