2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23534 | MEDIUM | 6.5 | 0.4% | Feb 14, 2025 | Missing Authorization vulnerability in Mark Winiarski WPLingo wplingo allows Exploiting Incorrectly Configured Access Co... |
| CVE-2025-22702 | MEDIUM | 6.3 | 0.3% | Feb 14, 2025 | Missing Authorization vulnerability in ThemeGoods Photography photography allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-22698 | MEDIUM | 6.3 | 0.3% | Feb 14, 2025 | Missing Authorization vulnerability in Ability, Inc Accessibility Suite online-accessibility allows Exploiting Incorrect... |
| CVE-2025-26524 | MEDIUM | 5.1 | 0.4% | Feb 14, 2025 | This vulnerability exists in RupeeWeb trading platform due to missing rate limiting on OTP requests in certain API endpo... |
| CVE-2025-0821 | MEDIUM | 6.5 | 0.5% | Feb 14, 2025 | Bit Assist plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, ... |
| CVE-2025-26791 | MEDIUM | 6.1 | 0.6% | Feb 14, 2025 | DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site sc... |
| CVE-2025-26789 | MEDIUM | 6.9 | 0.4% | Feb 14, 2025 | An issue was discovered in Logpoint AgentX before 1.5.0. A vulnerability caused by limited access controls allowed li-ad... |
| CVE-2025-23406 | MEDIUM | 5.3 | 0.4% | Feb 14, 2025 | Out-of-bounds read vulnerability caused by improper checking of TCP MSS option values exists in Cente middleware TCP/IP ... |
| CVE-2025-1053 | MEDIUM | 4.9 | 0.1% | Feb 14, 2025 | Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obt... |
| CVE-2025-25195 | MEDIUM | 4.3 | 0.3% | Feb 13, 2025 | Zulip is an open source team chat application. A weekly cron job (added in 50256f48314250978f521ef439cafa704e056539) dem... |
| CVE-2025-23421 | MEDIUM | 6.9 | 0.2% | Feb 13, 2025 | An attacker could obtain firmware files and reverse engineer their intended use leading to loss of confidentiality and ... |
| CVE-2025-23411 | MEDIUM | 6.5 | 0.6% | Feb 13, 2025 | mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sens... |
| CVE-2025-20615 | MEDIUM | 6.6 | 0.2% | Feb 13, 2025 | The Qardio Arm iOS application exposes sensitive data such as usernames and passwords in a plist file. This allows an a... |
| CVE-2025-24889 | MEDIUM | 4.5 | 0.2% | Feb 13, 2025 | The SecureDrop Client is a desktop application for journalists to communicate with sources and work with submissions on ... |
| CVE-2025-25900 | MEDIUM | 4.9 | 0.4% | Feb 13, 2025 | A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the username and password parameters at /us... |
| CVE-2025-25287 | MEDIUM | 4.7 | 0.3% | Feb 13, 2025 | Lakeus is a simple skin made for MediaWiki. Starting in version 1.0.8 and prior to versions 1.3.1+REL1.39, 1.3.1+REL1.42... |
| CVE-2025-0426 | MEDIUM | 6.2 | 0.3% | Feb 13, 2025 | A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthen... |
| CVE-2025-21701 | MEDIUM | 4.7 | 0.2% | Feb 13, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: avoid race between device unregistration and e... |
| CVE-2025-26574 | MEDIUM | 6.5 | 0.2% | Feb 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moch Amir Google D... |
| CVE-2025-26567 | MEDIUM | 6.5 | 0.2% | Feb 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in farjana55 Font Awe... |
| CVE-2025-26561 | MEDIUM | 5.9 | 0.2% | Feb 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elfsight Elfsight ... |
| CVE-2025-26558 | MEDIUM | 6.5 | 0.2% | Feb 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mkkmail Aparat Res... |
| CVE-2025-26539 | MEDIUM | 6.5 | 0.2% | Feb 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in petkivim Embed Goo... |
| CVE-2025-26538 | MEDIUM | 6.5 | 0.2% | Feb 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Prezi... |
| CVE-2025-1271 | MEDIUM | 6.1 | 0.3% | Feb 13, 2025 | Reflected Cross-Site Scripting (XSS) in Anapi Group's h6web. This security flaw could allow an attacker to inject malici... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now