2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1367 | MEDIUM | 5.3 | 0.3% | Feb 17, 2025 | A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux. It has been classified as critical. This affects... |
| CVE-2025-26779 | MEDIUM | 4.9 | 0.5% | Feb 16, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Fahad Mahmood Keep Backu... |
| CVE-2025-26767 | MEDIUM | 5.4 | 0.2% | Feb 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely qub... |
| CVE-2025-26766 | MEDIUM | 6.5 | 0.2% | Feb 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VaultDweller Leyka... |
| CVE-2025-26765 | MEDIUM | 5.4 | 0.2% | Feb 16, 2025 | Missing Authorization vulnerability in enituretechnology Distance Based Shipping Calculator distance-based-shipping-calc... |
| CVE-2025-26761 | MEDIUM | 6.5 | 0.2% | Feb 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Easy El... |
| CVE-2025-23975 | MEDIUM | 6.5 | 0.2% | Feb 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cheesefather Botne... |
| CVE-2025-22689 | MEDIUM | 6.5 | 0.2% | Feb 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Levan Tarbor Forex... |
| CVE-2025-22676 | MEDIUM | 6.5 | 0.2% | Feb 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in upcasted AWS S3 fo... |
| CVE-2025-22291 | MEDIUM | 5.3 | 0.3% | Feb 16, 2025 | Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – Worldwide Express Edition ltl-freight-quot... |
| CVE-2025-22284 | MEDIUM | 6.1 | 0.2% | Feb 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enituretechnology ... |
| CVE-2025-1364 | MEDIUM | 6.6 | 0.3% | Feb 16, 2025 | A vulnerability has been found in MicroWord eScan Antivirus 7.0.32 on Linux and classified as critical. Affected by this... |
| CVE-2025-1360 | MEDIUM | 5.1 | 0.3% | Feb 16, 2025 | A vulnerability, which was classified as problematic, was found in Internet Web Solutions Sublime CRM up to 20250207. Af... |
| CVE-2025-1359 | MEDIUM | 5.3 | 0.8% | Feb 16, 2025 | A vulnerability, which was classified as problematic, has been found in SIAM Industria de Automação e Monitoramento SIAM... |
| CVE-2025-1358 | MEDIUM | 5.3 | 0.2% | Feb 16, 2025 | A vulnerability classified as problematic was found in Pix Software Vivaz 6.0.10. This vulnerability affects unknown cod... |
| CVE-2025-1357 | MEDIUM | 5.3 | 0.4% | Feb 16, 2025 | A vulnerability classified as problematic has been found in Seventh D-Guard up to 20250206. This affects an unknown part... |
| CVE-2025-1354 | MEDIUM | 4.8 | 0.4% | Feb 16, 2025 | A cross-site scripting (XSS) vulnerability in the RT-N10E/ RT-N12E 2.0.0.x firmware . This vulnerability caused by impr... |
| CVE-2025-1337 | MEDIUM | 5.1 | 0.5% | Feb 16, 2025 | A vulnerability was found in Eastnets PaymentSafe 2.5.26.0. It has been classified as problematic. This affects an unkno... |
| CVE-2025-1332 | MEDIUM | 4.8 | 0.3% | Feb 16, 2025 | A vulnerability has been found in FastCMS up to 0.1.5 and classified as problematic. This vulnerability affects unknown ... |
| CVE-2025-0822 | MEDIUM | 6.5 | 0.6% | Feb 15, 2025 | Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the file... |
| CVE-2025-1005 | MEDIUM | 5.4 | 0.3% | Feb 15, 2025 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Imag... |
| CVE-2025-22209 | MEDIUM | 4.7 | 0.3% | Feb 15, 2025 | A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (admi... |
| CVE-2025-22208 | MEDIUM | 4.7 | 0.6% | Feb 15, 2025 | A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (admi... |
| CVE-2025-0935 | MEDIUM | 4.3 | 0.3% | Feb 15, 2025 | The Media Library Folders plugin for WordPress is vulnerable to unauthorized plugin settings change due to a missing cap... |
| CVE-2025-0996 | MEDIUM | 5.4 | 0.4% | Feb 15, 2025 | Inappropriate implementation in Browser UI in Google Chrome on Android prior to 133.0.6943.98 allowed a remote attacker ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now