2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0814 | MEDIUM | 6.9 | 0.4% | Feb 13, 2025 | CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the network services runnin... |
| CVE-2025-0661 | MEDIUM | 4.3 | 0.3% | Feb 13, 2025 | The DethemeKit For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inclu... |
| CVE-2025-0837 | MEDIUM | 5.4 | 0.2% | Feb 13, 2025 | The Puzzles theme for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and inclu... |
| CVE-2025-1198 | MEDIUM | 5.3 | 0.2% | Feb 13, 2025 | An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 pr... |
| CVE-2025-20097 | MEDIUM | 5.3 | 0.4% | Feb 12, 2025 | Uncaught exception in OpenBMC Firmware for the Intel(R) Server M50FCP Family and Intel(R) Server D50DNP Family before ve... |
| CVE-2025-1229 | MEDIUM | 6.3 | 1.5% | Feb 12, 2025 | A vulnerability classified as critical was found in olajowon Loggrove up to e428fac38cc480f011afcb1d8ce6c2bad378ddd6. Af... |
| CVE-2025-1228 | MEDIUM | 5.3 | 0.6% | Feb 12, 2025 | A vulnerability classified as problematic has been found in olajowon Loggrove up to e428fac38cc480f011afcb1d8ce6c2bad378... |
| CVE-2025-0113 | MEDIUM | 5.3 | 0.2% | Feb 12, 2025 | A problem with the network isolation mechanism of the Palo Alto Networks Cortex XDR Broker VM allows attackers unauthori... |
| CVE-2025-0111 | MEDIUM | 6.5 | 1.9% | Feb 12, 2025 | An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker wit... |
| CVE-2025-0109 | MEDIUM | 6.9 | 0.6% | Feb 12, 2025 | An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS management web interface enables an unau... |
| CVE-2025-1225 | MEDIUM | 6.3 | 0.4% | Feb 12, 2025 | A vulnerability, which was classified as problematic, has been found in ywoa up to 2024.07.03. This issue affects the fu... |
| CVE-2025-25201 | MEDIUM | 4 | 0.1% | Feb 12, 2025 | Nitrokey 3 Firmware is the the firmware of Nitrokey 3 USB keys. For release 1.8.0, and test releases with PIV enabled pr... |
| CVE-2025-25741 | MEDIUM | 5.4 | 0.4% | Feb 12, 2025 | D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the IPv6_PppoePass... |
| CVE-2025-1213 | MEDIUM | 5.4 | 0.5% | Feb 12, 2025 | A vulnerability was found in pihome-shc PiHome 1.77. It has been rated as problematic. Affected by this issue is some un... |
| CVE-2025-25184 | MEDIUM | 6.5 | 1.1% | Feb 12, 2025 | Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.11, 3.0.12, and 3.1.10, Rack::... |
| CVE-2025-1209 | MEDIUM | 5.4 | 0.3% | Feb 12, 2025 | A vulnerability classified as problematic has been found in code-projects Wazifa System 1.0. Affected is the function se... |
| CVE-2025-1208 | MEDIUM | 5.4 | 0.3% | Feb 12, 2025 | A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as problematic. This issue affects some ... |
| CVE-2025-0556 | MEDIUM | 6.5 | 0.3% | Feb 12, 2025 | In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework impleme... |
| CVE-2025-0516 | MEDIUM | 4.3 | 0.3% | Feb 12, 2025 | Improper Authorization in GitLab CE/EE affecting all versions from 17.7 prior to 17.7.4, 17.8 prior to 17.8.2 allow user... |
| CVE-2025-1202 | MEDIUM | 6.5 | 0.4% | Feb 12, 2025 | A vulnerability classified as critical has been found in SourceCodester Best Church Management Software 1.1. Affected is... |
| CVE-2025-0376 | MEDIUM | 6.1 | 0.4% | Feb 12, 2025 | An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4 and 1... |
| CVE-2025-26376 | MEDIUM | 6.5 | 0.3% | Feb 12, 2025 | A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 ... |
| CVE-2025-26374 | MEDIUM | 4.3 | 0.3% | Feb 12, 2025 | A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua (users endpoint) in Q-Free MaxTime less than or equal t... |
| CVE-2025-26373 | MEDIUM | 6.5 | 0.4% | Feb 12, 2025 | A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua (user endpoint) in Q-Free MaxTime less than or equal to... |
| CVE-2025-26367 | MEDIUM | 4.3 | 0.3% | Feb 12, 2025 | A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now