2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52430 | MEDIUM | 4.9 | 0.3% | Jan 2, 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote... |
| CVE-2025-52426 | MEDIUM | 4.9 | 0.3% | Jan 2, 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote... |
| CVE-2025-47208 | MEDIUM | 6.5 | 0.3% | Jan 2, 2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating... |
| CVE-2025-45286 | MEDIUM | 6.1 | 0.2% | Jan 2, 2026 | A cross-site scripting (XSS) vulnerability in mccutchen httpbin v2.17.1 allows attackers to execute arbitrary web script... |
| CVE-2025-44013 | MEDIUM | 6.5 | 0.3% | Jan 2, 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote... |
| CVE-2025-15437 | MEDIUM | 5.4 | 0.2% | Jan 2, 2026 | A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variabl... |
| CVE-2025-14072 | MEDIUM | 5.3 | 0.3% | Jan 2, 2026 | The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the... |
| CVE-2025-13456 | MEDIUM | 6.1 | 0.2% | Jan 2, 2026 | The ShopBuilder WordPress plugin before 3.2.2 does not sanitise and escape a parameter before outputting it back in the... |
| CVE-2025-13153 | MEDIUM | 6.1 | 0.2% | Jan 2, 2026 | The Logo Slider WordPress plugin before 4.9.0 does not validate and escape some of its slider options before outputting... |
| CVE-2025-12685 | MEDIUM | 6.5 | 0.1% | Jan 2, 2026 | The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthentica... |
| CVE-2025-14047 | MEDIUM | 5.3 | 0.2% | Jan 2, 2026 | The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User ... |
| CVE-2025-15419 | MEDIUM | 5.5 | 0.2% | Jan 2, 2026 | A weakness has been identified in Open5GS up to 2.7.6. Affected by this issue is the function sgwc_s5c_handle_create_ses... |
| CVE-2025-15418 | MEDIUM | 5.5 | 0.2% | Jan 2, 2026 | A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function ogs_gtp2_pars... |
| CVE-2025-15417 | MEDIUM | 5.5 | 0.2% | Jan 1, 2026 | A vulnerability was identified in Open5GS up to 2.7.6. Affected is the function sgwc_s11_handle_create_session_request o... |
| CVE-2025-15416 | MEDIUM | 5.4 | 0.2% | Jan 1, 2026 | A vulnerability was found in xnx3 wangmarket up to 6.4. This affects an unknown function of the file /siteVar/save.do of... |
| CVE-2025-15415 | MEDIUM | 5.4 | 0.2% | Jan 1, 2026 | A vulnerability has been found in xnx3 wangmarket up to 6.4. The impacted element is the function uploadImage of the fil... |
| CVE-2025-15414 | MEDIUM | 4.7 | 0.2% | Jan 1, 2026 | A flaw has been found in go-sonic sonic up to 1.1.4. The affected element is the function FetchTheme of the file service... |
| CVE-2025-68273 | MEDIUM | 5.3 | 0.3% | Jan 1, 2026 | Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure ... |
| CVE-2025-48768 | MEDIUM | 6.5 | 0.8% | Jan 1, 2026 | Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX... |
| CVE-2025-14627 | MEDIUM | 6.4 | 0.2% | Jan 1, 2026 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forger... |
| CVE-2025-14428 | MEDIUM | 4.3 | 0.3% | Jan 1, 2026 | The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements plugin f... |
| CVE-2025-66023 | MEDIUM | 4.9 | 0.3% | Jan 1, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.5 have a Heap-Use-After-Fre... |
| CVE-2025-13820 | MEDIUM | 5.3 | 0.2% | Jan 1, 2026 | The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provid... |
| CVE-2025-69413 | MEDIUM | 5.3 | 0.4% | Jan 1, 2026 | In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username e... |
| CVE-2025-67711 | MEDIUM | 6.1 | 0.2% | Dec 31, 2025 | There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now