2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12640 | MEDIUM | 4.3 | 0.2% | Jan 8, 2026 | The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vul... |
| CVE-2025-12776 | MEDIUM | 5.4 | 0.1% | Jan 7, 2026 | The Report Builder component of the application stores user input directly in a web page and displays it to other users,... |
| CVE-2025-69255 | MEDIUM | 4 | 0.3% | Jan 7, 2026 | RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.77, a malformed g... |
| CVE-2025-69221 | MEDIUM | 4.3 | 0.2% | Jan 7, 2026 | LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control when que... |
| CVE-2025-69220 | MEDIUM | 5.9 | 0.3% | Jan 7, 2026 | LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file... |
| CVE-2025-61939 | MEDIUM | 4.4 | 0.2% | Jan 7, 2026 | An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authe... |
| CVE-2025-61782 | MEDIUM | 6.1 | 0.2% | Jan 7, 2026 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.... |
| CVE-2025-58441 | MEDIUM | 6.5 | 0.2% | Jan 7, 2026 | Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, there is a blind server-si... |
| CVE-2025-66837 | MEDIUM | 6.8 | 0.3% | Jan 7, 2026 | A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted... |
| CVE-2025-66686 | MEDIUM | 6.1 | 0.2% | Jan 7, 2026 | A stored Cross-Site Scripting (XSS) vulnerability exists in Perch CMS version 3.2. An authenticated attacker with admini... |
| CVE-2025-61489 | MEDIUM | 6.5 | 0.8% | Jan 7, 2026 | A command injection vulnerability in the shell_exec function of sonirico mcp-shell v0.3.1 allows attackers to execute ar... |
| CVE-2025-66838 | MEDIUM | 6.5 | 0.3% | Jan 7, 2026 | In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, a... |
| CVE-2025-62327 | MEDIUM | 4.9 | 0.2% | Jan 7, 2026 | In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credenti... |
| CVE-2025-49335 | MEDIUM | 4.9 | 0.1% | Jan 7, 2026 | Server-Side Request Forgery (SSRF) vulnerability in minnur External Media external-media allows Server Side Request Forg... |
| CVE-2025-6225 | MEDIUM | 6.9 | 0.9% | Jan 7, 2026 | Kieback&Peter Neutrino-GLT product is used for building management. It's web component "SM70 PHWEB" is vulnerable to she... |
| CVE-2025-15479 | MEDIUM | 5.4 | 0.2% | Jan 7, 2026 | Stored cross-site scripting (XSS, CWE-79) in the survey content and administration functionality in Data Illusion Zumbru... |
| CVE-2025-46434 | MEDIUM | 6.5 | 0.2% | Jan 7, 2026 | Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro theplus_elementor_addon all... |
| CVE-2025-46256 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | Path Traversal: '.../...//' vulnerability in SigmaPlugin Advanced Database Cleaner PRO allows Path Traversal.This issue ... |
| CVE-2025-69344 | MEDIUM | 4.3 | 0.2% | Jan 7, 2026 | Missing Authorization vulnerability in themehunk Oneline Lite oneline-lite allows Exploiting Incorrectly Configured Acce... |
| CVE-2025-69333 | MEDIUM | 4.3 | 0.2% | Jan 7, 2026 | Missing Authorization vulnerability in Crocoblock JetEngine jet-engine allows Exploiting Incorrectly Configured Access C... |
| CVE-2025-47395 | MEDIUM | 6.5 | 0.1% | Jan 7, 2026 | Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element. |
| CVE-2025-47369 | MEDIUM | 5.5 | 0.1% | Jan 7, 2026 | Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a ses... |
| CVE-2025-47344 | MEDIUM | 6.4 | 0.1% | Jan 7, 2026 | Memory corruption while handling sensor utility operations. |
| CVE-2025-47337 | MEDIUM | 6.7 | 0.1% | Jan 7, 2026 | Memory corruption while accessing a synchronization object during concurrent operations. |
| CVE-2025-47336 | MEDIUM | 6.7 | 0.1% | Jan 7, 2026 | Memory corruption while performing sensor register read operations. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now