2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47339 | HIGH | 7.8 | 0.1% | Jan 7, 2026 | Memory corruption while deinitializing a HDCP session. |
| CVE-2025-32300 | HIGH | 7.1 | 0.2% | Jan 7, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital zoom studi... |
| CVE-2025-31643 | HIGH | 8.8 | 0.3% | Jan 7, 2026 | Incorrect Privilege Assignment vulnerability in Dasinfomedia WPCHURCH allows Privilege Escalation.This issue affects WPC... |
| CVE-2025-15472 | HIGH | 7.3 | 20.1% | Jan 7, 2026 | A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0. This affects the function setDeviceURL of the file uapply.cgi of ... |
| CVE-2025-15158 | HIGH | 8.8 | 0.4% | Jan 7, 2026 | The WP Enable WebP plugin for WordPress is vulnerable to arbitrary file uploads due to improper file type validation in ... |
| CVE-2025-14835 | HIGH | 7.1 | 0.2% | Jan 7, 2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ paramet... |
| CVE-2025-14804 | HIGH | 7.7 | 0.2% | Jan 7, 2026 | The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership of the fil... |
| CVE-2025-14070 | HIGH | 7.5 | 0.4% | Jan 7, 2026 | The Reviewify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ... |
| CVE-2025-13801 | HIGH | 7.5 | 1.7% | Jan 7, 2026 | The Yoco Payments plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.9.0 via t... |
| CVE-2025-13493 | HIGH | 7.5 | 0.3% | Jan 7, 2026 | The Latest Registered Users plugin for WordPress is vulnerable to unauthorized user data export in all versions up to, a... |
| CVE-2025-13371 | HIGH | 8.6 | 0.4% | Jan 7, 2026 | The MoneySpace plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including... |
| CVE-2025-11877 | HIGH | 7.5 | 0.3% | Jan 7, 2026 | The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2.2. The failed... |
| CVE-2025-11235 | HIGH | 7.5 | 0.2% | Jan 7, 2026 | Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MO... |
| CVE-2025-31642 | HIGH | 7.1 | 0.1% | Jan 7, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dasinfomedia WPCHU... |
| CVE-2025-30631 | HIGH | 7.1 | 0.1% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team Woocommerc... |
| CVE-2025-29004 | HIGH | 8.8 | 0.3% | Jan 6, 2026 | Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Re... |
| CVE-2025-32304 | HIGH | 8.1 | 0.3% | Jan 6, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-15382 | HIGH | 8.1 | 0.3% | Jan 6, 2026 | A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote att... |
| CVE-2025-69356 | HIGH | 7.5 | 0.3% | Jan 6, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-69351 | HIGH | 8.5 | 0.2% | Jan 6, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ni... |
| CVE-2025-69342 | HIGH | 7.5 | 0.3% | Jan 6, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-69086 | HIGH | 8.1 | 0.3% | Jan 6, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-69085 | HIGH | 7.1 | 0.2% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins JobBank ... |
| CVE-2025-69084 | HIGH | 7.1 | 0.2% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Ga... |
| CVE-2025-69083 | HIGH | 8.1 | 0.3% | Jan 6, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now