2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22260 | MEDIUM | 4.3 | 0.3% | Feb 3, 2025 | Missing Authorization vulnerability in Marcus (aka @msykes) Meta Tag Manager meta-tag-manager.This issue affects Meta Ta... |
| CVE-2025-25063 | MEDIUM | 4.4 | 0.2% | Feb 3, 2025 | An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It does not sufficiently vali... |
| CVE-2025-25062 | MEDIUM | 4.4 | 1.6% | Feb 3, 2025 | An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isola... |
| CVE-2025-20642 | MEDIUM | 6.6 | 0.1% | Feb 3, 2025 | In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pri... |
| CVE-2025-20641 | MEDIUM | 6.6 | 0.1% | Feb 3, 2025 | In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pri... |
| CVE-2025-20640 | MEDIUM | 4.3 | 0.1% | Feb 3, 2025 | In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclo... |
| CVE-2025-20639 | MEDIUM | 6.6 | 0.1% | Feb 3, 2025 | In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pri... |
| CVE-2025-20638 | MEDIUM | 4.3 | 0.1% | Feb 3, 2025 | In DA, there is a possible read of uninitialized heap data due to uninitialized data. This could lead to local informati... |
| CVE-2025-20636 | MEDIUM | 6.7 | 0.1% | Feb 3, 2025 | In secmem, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of... |
| CVE-2025-20635 | MEDIUM | 6.6 | 0.1% | Feb 3, 2025 | In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of ... |
| CVE-2025-0974 | MEDIUM | 5 | 0.4% | Feb 3, 2025 | A vulnerability was determined in MaxD Lightning Module 4.43/4.44 on OpenCart. This issue affects some unknown processin... |
| CVE-2025-0973 | MEDIUM | 6.5 | 0.8% | Feb 3, 2025 | A vulnerability classified as critical was found in CmsEasy 7.7.7.9. This vulnerability affects the function backAll_act... |
| CVE-2025-0972 | MEDIUM | 5.4 | 0.3% | Feb 3, 2025 | A vulnerability classified as problematic has been found in Zenvia Movidesk up to 25.01.22. This affects an unknown part... |
| CVE-2025-0971 | MEDIUM | 5.4 | 0.3% | Feb 3, 2025 | A vulnerability was found in Zenvia Movidesk up to 25.01.22. It has been rated as problematic. Affected by this issue is... |
| CVE-2025-0970 | MEDIUM | 6.1 | 0.4% | Feb 2, 2025 | A vulnerability was found in Zenvia Movidesk up to 25.01.22. It has been declared as problematic. Affected by this vulne... |
| CVE-2025-0961 | MEDIUM | 5.4 | 0.4% | Feb 1, 2025 | A vulnerability, which was classified as problematic, has been found in code-projects Job Recruitment 1.0. Affected by t... |
| CVE-2025-23091 | MEDIUM | 5.9 | 0.2% | Feb 1, 2025 | An Improper Certificate Validation on UniFi OS devices, with Identity Enterprise configured, could allow a malicious act... |
| CVE-2025-0939 | MEDIUM | 6.3 | 0.3% | Feb 1, 2025 | The MagicForm plugin for WordPress is vulnerable to access and modification of data due to a missing capability check on... |
| CVE-2025-0365 | MEDIUM | 6.5 | 0.7% | Feb 1, 2025 | The Jupiter X Core plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.8.7... |
| CVE-2025-0938 | MEDIUM | 6.3 | 1.5% | Jan 31, 2025 | The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square ... |
| CVE-2025-23001 | MEDIUM | 6.1 | 0.3% | Jan 31, 2025 | A Host header injection vulnerability exists in CTFd 3.7.5, due to the application failing to properly validate or sanit... |
| CVE-2025-22994 | MEDIUM | 6.1 | 0.3% | Jan 31, 2025 | O2OA 9.1.3 is vulnerable to Cross Site Scripting (XSS) in Meetings - Settings. |
| CVE-2025-0930 | MEDIUM | 6.1 | 0.2% | Jan 31, 2025 | Reflected Cross-Site Scripting (XSS) in TeamCal Neo, version 3.8.2. This allows an attacker to execute malicious JavaScr... |
| CVE-2025-24831 | MEDIUM | 6.6 | 0.2% | Jan 31, 2025 | Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber... |
| CVE-2025-24830 | MEDIUM | 6.3 | 0.1% | Jan 31, 2025 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now