2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61549 | MEDIUM | 6.1 | 0.2% | Jan 8, 2026 | Cross-Site Scripting (XSS) is present on the LoginID parameter on the /PSP/app/web/reg/reg_display.asp endpoint in edu B... |
| CVE-2025-61547 | MEDIUM | 6.8 | 0.1% | Jan 8, 2026 | Cross-Site Request Forgery (CSRF) is present on all functions in edu Business Solutions Print Shop Pro WebDesk version 1... |
| CVE-2025-67091 | MEDIUM | 6.5 | 3.0% | Jan 8, 2026 | An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL.... |
| CVE-2025-67090 | MEDIUM | 5.1 | 0.2% | Jan 8, 2026 | The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL... |
| CVE-2025-67603 | MEDIUM | 5.1 | 0.1% | Jan 8, 2026 | A Improper Authorization vulnerability in Foomuuri llows arbitrary users to influence the firewall configuration.This is... |
| CVE-2025-66002 | MEDIUM | 6.9 | 0.1% | Jan 8, 2026 | An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability allows local users ... |
| CVE-2025-4596 | MEDIUM | 5.3 | 0.3% | Jan 8, 2026 | Asseco ADMX system is used for processing medical records. It allows logged in users to access medical files belonging t... |
| CVE-2025-8307 | MEDIUM | 5.9 | 0.1% | Jan 8, 2026 | Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sec... |
| CVE-2025-8306 | MEDIUM | 5.1 | 0.1% | Jan 8, 2026 | Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sec... |
| CVE-2025-69169 | MEDIUM | 5.4 | 0.2% | Jan 8, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Noor Alam Easy Media Down... |
| CVE-2025-68875 | MEDIUM | 6.5 | 0.1% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jcaruso001 Flaming... |
| CVE-2025-68867 | MEDIUM | 6.5 | 0.2% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in anibalwainstein Ef... |
| CVE-2025-67926 | MEDIUM | 6.5 | 0.3% | Jan 8, 2026 | Missing Authorization vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Exploiting Incorrectly Confi... |
| CVE-2025-67919 | MEDIUM | 6.5 | 0.3% | Jan 8, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in WofficeIO Woffice Core woffice-core allows Exploiting ... |
| CVE-2025-67917 | MEDIUM | 6.5 | 0.2% | Jan 8, 2026 | Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2025-67913 | MEDIUM | 6.5 | 0.2% | Jan 8, 2026 | Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Accessing Functionali... |
| CVE-2025-22726 | MEDIUM | 6.4 | 0.2% | Jan 8, 2026 | Server-Side Request Forgery (SSRF) vulnerability in _nK nK Themes Helper nk-themes-helper allows Server Side Request For... |
| CVE-2025-15079 | MEDIUM | 5.3 | 0.5% | Jan 8, 2026 | When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenl... |
| CVE-2025-14984 | MEDIUM | 6.4 | 0.3% | Jan 8, 2026 | The Gutenverse Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all version... |
| CVE-2025-14819 | MEDIUM | 5.3 | 0.7% | Jan 8, 2026 | When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option... |
| CVE-2025-14524 | MEDIUM | 5.3 | 0.6% | Jan 8, 2026 | When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a s... |
| CVE-2025-14017 | MEDIUM | 6.3 | 0.1% | Jan 8, 2026 | When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadver... |
| CVE-2025-13034 | MEDIUM | 5.9 | 0.2% | Jan 8, 2026 | When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey` with the curl tool,curl should check the pu... |
| CVE-2025-13679 | MEDIUM | 6.5 | 0.2% | Jan 8, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of data d... |
| CVE-2025-14275 | MEDIUM | 6.4 | 0.2% | Jan 8, 2026 | The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now