2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70058 | HIGH | 7.4 | 0.2% | Feb 23, 2026 | An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application dis... |
| CVE-2025-70045 | HIGH | 7.4 | 0.2% | Feb 23, 2026 | An issue pertaining to CWE-295: Improper Certificate Validation was discovered in jxcore jxm master. The application dis... |
| CVE-2025-70044 | MEDIUM | 6.5 | 0.1% | Feb 23, 2026 | An issue pertaining to CWE-295: Improper Certificate Validation was discovered in fofolee uTools-quickcommand 5.0.3. |
| CVE-2025-70043 | CRITICAL | 9.1 | 0.2% | Feb 23, 2026 | An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application d... |
| CVE-2025-14905 | HIGH | 7.2 | 1.0% | Feb 23, 2026 | A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callbac... |
| CVE-2025-69700 | HIGH | 7.5 | 3.5% | Feb 23, 2026 | Tenda FH1203 V2.0.1.6 contains a stack-based buffer overflow vulnerability in the modify_add_client_prio function, which... |
| CVE-2025-59873 | MEDIUM | 5.9 | 0.3% | Feb 23, 2026 | An information exposure vulnerability exists in Vulnerability in HCL Software ZIE for Web. The application transmits s... |
| CVE-2025-40986 | MEDIUM | 5.1 | 0.4% | Feb 23, 2026 | Reflected Cross-Site Scripting (XSS) vulnerability in PideTuCita. This vulnerability allows an attacker to execute JavaS... |
| CVE-2025-40701 | MEDIUM | 5.1 | 0.4% | Feb 23, 2026 | Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute J... |
| CVE-2025-41002 | CRITICAL | 9.3 | 0.3% | Feb 23, 2026 | SQL injection vulnerability in Infoticketing. This vulnerability allows an unauthenticated attacker to retrieve, create... |
| CVE-2025-14339 | MEDIUM | 6.5 | 0.3% | Feb 21, 2026 | The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for Wo... |
| CVE-2025-65995 | MEDIUM | 6.5 | 0.8% | Feb 21, 2026 | When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operat... |
| CVE-2025-62326 | MEDIUM | 4.8 | 0.2% | Feb 20, 2026 | HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which wo... |
| CVE-2025-70833 | CRITICAL | 9.4 | 0.4% | Feb 20, 2026 | An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any u... |
| CVE-2025-15583 | MEDIUM | 5.4 | 0.2% | Feb 20, 2026 | A weakness has been identified in detronetdip E-commerce 1.0.0. This affects the function get_safe_value of the file uti... |
| CVE-2025-15582 | HIGH | 8.1 | 0.3% | Feb 20, 2026 | A security flaw has been discovered in detronetdip E-commerce 1.0.0. The impacted element is the function Delete/Update ... |
| CVE-2025-70831 | CRITICAL | 9.8 | 0.9% | Feb 20, 2026 | A Remote Code Execution (RCE) vulnerability was found in Smanga 3.2.7 in the /php/path/rescan.php interface. The applica... |
| CVE-2025-69410 | HIGH | 8.1 | 0.5% | Feb 20, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-69409 | HIGH | 8.1 | 0.5% | Feb 20, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-69408 | HIGH | 8.1 | 0.5% | Feb 20, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-69407 | HIGH | 8.1 | 0.5% | Feb 20, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-69406 | HIGH | 8.1 | 0.5% | Feb 20, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-69405 | CRITICAL | 9.8 | 0.4% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Lorem Ipsum | Books & Media Store lorem-ipsum-books-media-st... |
| CVE-2025-69404 | CRITICAL | 9.8 | 0.4% | Feb 20, 2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Extreme Store extremestore allows Object Injection.This issu... |
| CVE-2025-69403 | CRITICAL | 9.9 | 0.4% | Feb 20, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Bravis-Themes Bravis Addons bravis-addons allows Using ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now