2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-21401 | MEDIUM | 4.5 | 0.3% | Feb 15, 2025 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2025-25304 | MEDIUM | 6.9 | 0.6% | Feb 14, 2025 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design... |
| CVE-2025-25296 | MEDIUM | 6.1 | 1.8% | Feb 14, 2025 | Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's `/projects/upload-example` en... |
| CVE-2025-25290 | MEDIUM | 5.3 | 0.7% | Feb 14, 2025 | @octokit/request sends parameterized requests to GitHub’s APIs with sensible defaults in browsers and Node. Starting in ... |
| CVE-2025-25289 | MEDIUM | 5.3 | 0.6% | Feb 14, 2025 | @octokit/request-error is an error class for Octokit request errors. Starting in version 1.0.0 and prior to version 6.1.... |
| CVE-2025-25288 | MEDIUM | 5.3 | 0.6% | Feb 14, 2025 | @octokit/plugin-paginate-rest is the Octokit plugin to paginate REST API endpoint responses. For versions starting in 1.... |
| CVE-2025-25285 | MEDIUM | 5.3 | 0.6% | Feb 14, 2025 | @octokit/endpoint turns REST API endpoints into generic request options. Starting in version 4.1.0 and prior to version ... |
| CVE-2025-0503 | MEDIUM | 5.3 | 0.2% | Feb 14, 2025 | Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker ... |
| CVE-2025-26158 | MEDIUM | 5.6 | 0.3% | Feb 14, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the manage-employee.php page of Kashipara Online Att... |
| CVE-2025-26157 | MEDIUM | 5.9 | 0.3% | Feb 14, 2025 | A SQL Injection vulnerability was found in /bpms/index.php in Source Code and Project Beauty Parlour Management System V... |
| CVE-2025-25993 | MEDIUM | 5.1 | 0.3% | Feb 14, 2025 | SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the para... |
| CVE-2025-25992 | MEDIUM | 5.1 | 0.3% | Feb 14, 2025 | SQL Injection vulnerability in FeMiner wms 1.0 allows a remote attacker to obtain sensitive information via the inquire_... |
| CVE-2025-25991 | MEDIUM | 5.1 | 0.2% | Feb 14, 2025 | SQL Injection vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /instal... |
| CVE-2025-25990 | MEDIUM | 6.1 | 0.3% | Feb 14, 2025 | Cross Site Scripting vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the ... |
| CVE-2025-25988 | MEDIUM | 4.8 | 0.2% | Feb 14, 2025 | Cross Site Scripting vulnerability in hooskcms v.1.8 allows a remote attacker to cause a denial of service via the custo... |
| CVE-2025-25204 | MEDIUM | 6.3 | 0.4% | Feb 14, 2025 | `gh` is GitHub’s official command line tool. Starting in version 2.49.0 and prior to version 2.67.0, under certain condi... |
| CVE-2025-25740 | MEDIUM | 5.5 | 0.3% | Feb 14, 2025 | D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the PSK parameter ... |
| CVE-2025-1239 | MEDIUM | 4.8 | 0.4% | Feb 14, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances vi... |
| CVE-2025-1071 | MEDIUM | 4.8 | 0.2% | Feb 14, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances vi... |
| CVE-2025-0178 | MEDIUM | 6.1 | 0.2% | Feb 14, 2025 | An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker with network access to manipulat... |
| CVE-2025-24700 | MEDIUM | 6.1 | 0.2% | Feb 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xylus Themes WP Ev... |
| CVE-2025-24567 | MEDIUM | 6.5 | 0.4% | Feb 14, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster wp-mailster allows Retrieve Emb... |
| CVE-2025-23857 | MEDIUM | 6.1 | 0.2% | Feb 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SmartDataSoft Esse... |
| CVE-2025-23771 | MEDIUM | 6.5 | 0.4% | Feb 14, 2025 | Missing Authorization vulnerability in Murali Push Notification for Post and BuddyPress push-notification-for-post-and-b... |
| CVE-2025-23766 | MEDIUM | 6.5 | 0.4% | Feb 14, 2025 | Missing Authorization vulnerability in ashamil OPSI Israel Domestic Shipments woo-ups-pickup allows Exploiting Incorrect... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now