2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14001 | MEDIUM | 5.4 | 0.2% | Jan 13, 2026 | The WP Duplicate Page plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability ... |
| CVE-2025-68657 | MEDIUM | 6.4 | 0.1% | Jan 12, 2026 | Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, calls to hi... |
| CVE-2025-68656 | MEDIUM | 6.8 | 0.2% | Jan 12, 2026 | Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, usb_class_r... |
| CVE-2025-68471 | MEDIUM | 6.5 | 0.4% | Jan 12, 2026 | Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 ... |
| CVE-2025-68468 | MEDIUM | 6.5 | 0.3% | Jan 12, 2026 | Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 ... |
| CVE-2025-68276 | MEDIUM | 5.5 | 0.1% | Jan 12, 2026 | Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 ... |
| CVE-2025-68622 | MEDIUM | 6.8 | 0.2% | Jan 12, 2026 | Espressif ESP-IDF USB Host UVC Class Driver allows video streaming from USB cameras. Prior to 2.4.0, a vulnerability in ... |
| CVE-2025-66689 | MEDIUM | 6.5 | 0.5% | Jan 12, 2026 | A path traversal vulnerability exists in Zen MCP Server before 9.8.2 that allows authenticated attackers to read arbitra... |
| CVE-2025-67813 | MEDIUM | 5.3 | 0.2% | Jan 12, 2026 | Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communica... |
| CVE-2025-66939 | MEDIUM | 5.4 | 0.2% | Jan 12, 2026 | Cross Site Scripting vulnerability in 66biolinks by AltumCode v.61.0.1 allows an attacker to execute arbitrary code via ... |
| CVE-2025-65553 | MEDIUM | 6.5 | 0.2% | Jan 12, 2026 | D3D Wi-Fi Home Security System ZX-G12 v2.1.17 is susceptible to RF jamming on the 433 MHz alarm sensor channel. An attac... |
| CVE-2025-41003 | MEDIUM | 5.1 | 0.3% | Jan 12, 2026 | Imaster's Patient Record Management System contains a stored Cross-Site Scripting (XSS) vulnerability in the endpoint ‘/... |
| CVE-2025-40978 | MEDIUM | 5.1 | 0.3% | Jan 12, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a stored XSS due to a lack o... |
| CVE-2025-40977 | MEDIUM | 5.1 | 0.3% | Jan 12, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a lack of proper validation ... |
| CVE-2025-40976 | MEDIUM | 5.1 | 0.3% | Jan 12, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's TicketGo, consisting of a lack of proper validation of user ... |
| CVE-2025-40975 | MEDIUM | 5.1 | 0.3% | Jan 12, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's HRMGo, consisting of a lack of proper validation of user inp... |
| CVE-2025-14579 | MEDIUM | 4.8 | 0.2% | Jan 12, 2026 | The Quiz Maker WordPress plugin before 6.7.0.89 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2025-69275 | MEDIUM | 6.1 | 0.1% | Jan 12, 2026 | Dependency on Vulnerable Third-Party Component vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows DOM... |
| CVE-2025-69268 | MEDIUM | 6.1 | 0.1% | Jan 12, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Broadcom DX... |
| CVE-2025-69267 | MEDIUM | 6.5 | 0.3% | Jan 12, 2026 | Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectru... |
| CVE-2025-13393 | MEDIUM | 4.3 | 0.2% | Jan 10, 2026 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up ... |
| CVE-2025-12379 | MEDIUM | 6.4 | 0.2% | Jan 10, 2026 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2025-14555 | MEDIUM | 6.4 | 0.2% | Jan 10, 2026 | The Countdown Timer – Widget Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'... |
| CVE-2025-15504 | MEDIUM | 5.5 | 0.2% | Jan 10, 2026 | A security flaw has been discovered in lief-project LIEF up to 0.17.1. Affected by this issue is the function Parser::pa... |
| CVE-2025-14506 | MEDIUM | 6.4 | 0.2% | Jan 10, 2026 | The ConvertForce Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gutenberg block... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now