2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-25469 | MEDIUM | 6.5 | 0.3% | Feb 18, 2025 | FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/iamf.c. |
| CVE-2025-25468 | MEDIUM | 6.5 | 0.4% | Feb 18, 2025 | FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/mem.c. |
| CVE-2025-22921 | MEDIUM | 6.5 | 0.3% | Feb 18, 2025 | FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/... |
| CVE-2025-27016 | MEDIUM | 6.5 | 0.2% | Feb 18, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awsm.in Drivr Lite... |
| CVE-2025-27013 | MEDIUM | 5.3 | 0.3% | Feb 18, 2025 | Missing Authorization vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Exploiting Inco... |
| CVE-2025-22650 | MEDIUM | 6.5 | 0.2% | Feb 18, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnens... |
| CVE-2025-22645 | MEDIUM | 5.3 | 0.3% | Feb 18, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Rameez Iqbal Real Estate Manager real-estate-... |
| CVE-2025-0622 | MEDIUM | 6.4 | 0.3% | Feb 18, 2025 | A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related mod... |
| CVE-2025-26603 | MEDIUM | 4.2 | 0.2% | Feb 18, 2025 | Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the `:red... |
| CVE-2025-26465 | MEDIUM | 6.8 | 7.6% | Feb 18, 2025 | A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be ... |
| CVE-2025-21608 | MEDIUM | 5.3 | 0.3% | Feb 18, 2025 | Meshtastic is an open source mesh networking solution. In affected firmware versions crafted packets over MQTT are able ... |
| CVE-2025-26620 | MEDIUM | 6.3 | 0.4% | Feb 18, 2025 | Duende.AccessTokenManagement is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. Duende.Acces... |
| CVE-2025-26058 | MEDIUM | 4.2 | 0.2% | Feb 18, 2025 | Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or oth... |
| CVE-2025-22207 | MEDIUM | 6.7 | 0.4% | Feb 18, 2025 | Improperly built order clauses lead to a SQL injection vulnerability in the backend task list of com_scheduler. |
| CVE-2025-1414 | MEDIUM | 6.5 | 0.4% | Feb 18, 2025 | Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption and we presume that w... |
| CVE-2025-1269 | MEDIUM | 4.8 | 0.2% | Feb 18, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HAVELSAN Liman MYS allows Cross-Site Flashing. Thi... |
| CVE-2025-1035 | MEDIUM | 5.7 | 9.8% | Feb 18, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog... |
| CVE-2025-0817 | MEDIUM | 6.1 | 0.3% | Feb 18, 2025 | The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up ... |
| CVE-2025-0521 | MEDIUM | 6.1 | 0.3% | Feb 18, 2025 | The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the from and subject parameter in al... |
| CVE-2025-0981 | MEDIUM | 6.1 | 0.2% | Feb 18, 2025 | A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a ... |
| CVE-2025-0864 | MEDIUM | 6.1 | 0.4% | Feb 18, 2025 | The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Refle... |
| CVE-2025-0424 | MEDIUM | 5.1 | 0.4% | Feb 18, 2025 | In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated ... |
| CVE-2025-0423 | MEDIUM | 5.3 | 0.5% | Feb 18, 2025 | In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple unauthenticate... |
| CVE-2025-0805 | MEDIUM | 5.4 | 0.3% | Feb 18, 2025 | The Mortgage Calculator / Loan Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug... |
| CVE-2025-0796 | MEDIUM | 4.3 | 0.2% | Feb 18, 2025 | The Mortgage Lead Capture System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now