2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39497 | MEDIUM | 6.5 | 0.1% | Jan 5, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan Dokan Pro al... |
| CVE-2025-10933 | MEDIUM | 5.3 | 0.2% | Jan 5, 2026 | An integer underflow vulnerability in the Silicon Labs Z-Wave Protocol Controller can lead to out of bounds memory reads... |
| CVE-2025-65328 | MEDIUM | 6.5 | 0.2% | Jan 5, 2026 | Mega-Fence (webgate-lib.*) 25.1.914 and prior trusts the first value of the X-Forwarded-For (XFF) header as the client I... |
| CVE-2025-66376 | MEDIUM | 6.1 | 12.0% | Jan 5, 2026 | Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sh... |
| CVE-2025-68280 | MEDIUM | 6.5 | 0.6% | Jan 5, 2026 | Improper Restriction of XML External Entity Reference vulnerability in Apache SIS. It is possible to write XML files ... |
| CVE-2025-12513 | MEDIUM | 4.8 | 0.2% | Jan 5, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-12511 | MEDIUM | 4.8 | 0.2% | Jan 5, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-68029 | MEDIUM | 6.3 | 0.2% | Jan 5, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WP Swings Wallet System for WooCommerce wallet-system... |
| CVE-2025-68014 | MEDIUM | 6.5 | 0.2% | Jan 5, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in awethemes AweBooking awebooking allows Retrieve Embed... |
| CVE-2025-31046 | MEDIUM | 4.3 | 0.2% | Jan 5, 2026 | Missing Authorization vulnerability in WPvibes AnyWhere Elementor Pro allows Exploiting Incorrectly Configured Access Co... |
| CVE-2025-13056 | MEDIUM | 4.8 | 0.2% | Jan 5, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-12519 | MEDIUM | 5.3 | 0.2% | Jan 5, 2026 | Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows... |
| CVE-2025-15237 | MEDIUM | 5.3 | 0.3% | Jan 5, 2026 | QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticat... |
| CVE-2025-15236 | MEDIUM | 5.3 | 0.3% | Jan 5, 2026 | QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticat... |
| CVE-2025-15022 | MEDIUM | 4.8 | 0.3% | Jan 5, 2026 | Action captions in Vaadin accept HTML by default but were not sanitized, potentially allowing Cross-site Scripting (XSS)... |
| CVE-2025-15455 | MEDIUM | 6.5 | 0.6% | Jan 5, 2026 | A flaw has been found in bg5sbk MiniCMS up to 1.8. Impacted is the function delete_page of the file /minicms/mc-admin/pa... |
| CVE-2025-15453 | MEDIUM | 6.3 | 0.3% | Jan 5, 2026 | A security vulnerability has been detected in milvus up to 2.6.7. This vulnerability affects the function expr.Exec of t... |
| CVE-2025-15452 | MEDIUM | 4.8 | 0.2% | Jan 5, 2026 | A weakness has been identified in xnx3 wangmarket up to 4.9. This affects the function variableList of the file /admin/s... |
| CVE-2025-15451 | MEDIUM | 4.8 | 0.2% | Jan 5, 2026 | A security flaw has been discovered in xnx3 wangmarket up to 4.9. Affected by this issue is some unknown functionality o... |
| CVE-2025-15450 | MEDIUM | 6.3 | 0.3% | Jan 5, 2026 | A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected by this v... |
| CVE-2025-5591 | MEDIUM | 5.4 | 0.1% | Jan 5, 2026 | Kentico Xperience 13 is vulnerable to a stored cross-site scripting attack via a form component, allowing an attacker to... |
| CVE-2025-14830 | MEDIUM | 4.9 | 0.2% | Jan 4, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in JFrog Artif... |
| CVE-2025-3652 | MEDIUM | 6.9 | 0.2% | Jan 4, 2026 | Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows un... |
| CVE-2025-64122 | MEDIUM | 5.5 | 0.1% | Jan 2, 2026 | Insufficiently Protected Credentials vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Signature Spoo... |
| CVE-2025-69417 | MEDIUM | 4.3 | 0.3% | Jan 2, 2026 | In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share toke... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now