2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14034 | MEDIUM | 5.3 | 0.2% | Jan 6, 2026 | The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of d... |
| CVE-2025-13746 | MEDIUM | 6.4 | 0.2% | Jan 6, 2026 | The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User's ... |
| CVE-2025-13652 | MEDIUM | 6.5 | 1.1% | Jan 6, 2026 | The CBX Bookmark & Favorite plugin for WordPress is vulnerable to generic SQL Injection via the ‘orderby’ parameter in a... |
| CVE-2025-13409 | MEDIUM | 4.9 | 0.3% | Jan 6, 2026 | The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to SQL Injection via the 'params' paramet... |
| CVE-2025-11723 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sen... |
| CVE-2025-11370 | MEDIUM | 5.3 | 0.2% | Jan 6, 2026 | The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel... |
| CVE-2025-20807 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In dpe, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privi... |
| CVE-2025-20806 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if... |
| CVE-2025-20805 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if... |
| CVE-2025-20804 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if... |
| CVE-2025-20803 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In dpe, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privile... |
| CVE-2025-20802 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privil... |
| CVE-2025-20794 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service... |
| CVE-2025-20793 | MEDIUM | 6.5 | 0.3% | Jan 6, 2026 | In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,... |
| CVE-2025-20787 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg... |
| CVE-2025-20786 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg... |
| CVE-2025-20785 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg... |
| CVE-2025-20784 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In display, there is a possible memory corruption due to uninitialized data. This could lead to local escalation of priv... |
| CVE-2025-20783 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o... |
| CVE-2025-20782 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o... |
| CVE-2025-20762 | MEDIUM | 6.5 | 0.3% | Jan 6, 2026 | In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,... |
| CVE-2025-20761 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,... |
| CVE-2025-20760 | MEDIUM | 6.5 | 0.3% | Jan 6, 2026 | In Modem, there is a possible read of uninitialized heap data due to an uncaught exception. This could lead to remote de... |
| CVE-2025-69197 | MEDIUM | 6.5 | 0.3% | Jan 6, 2026 | Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multip... |
| CVE-2025-68954 | MEDIUM | 5.4 | 0.2% | Jan 6, 2026 | Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP co... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now