2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53233 | HIGH | 7.1 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RylanH Storyform s... |
| CVE-2025-53231 | HIGH | 7.1 | 0.3% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevstudio Easy T... |
| CVE-2025-53228 | HIGH | 7.1 | 0.3% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jezza101 bbpress S... |
| CVE-2025-53217 | HIGH | 7.6 | 0.2% | Feb 20, 2026 | Missing Authorization vulnerability in staviravn AIO WP Builder all-in-one-wp-builder allows Exploiting Incorrectly Conf... |
| CVE-2025-52744 | HIGH | 7.7 | 0.3% | Feb 20, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in inpersttion Inpersttion For Theme err-our-tea... |
| CVE-2025-52603 | LOW | 3.5 | 0.3% | Feb 20, 2026 | HCL Connections is vulnerable to information disclosure. In a very specific user navigation scenario, this could allow ... |
| CVE-2025-14547 | LOW | 2.3 | 0.3% | Feb 20, 2026 | An integer underflow vulnerability is present in Silicon Lab’s implementation of PSA Crypto and SE Manager EC-JPAKE APIs... |
| CVE-2025-14055 | LOW | 2.4 | 0.2% | Feb 20, 2026 | An integer underflow vulnerability in Silicon Labs Secure NCP host implementation allows a buffer overread via a special... |
| CVE-2025-10970 | CRITICAL | 9.8 | 0.3% | Feb 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kolay Software Inc... |
| CVE-2025-59819 | MEDIUM | 6.5 | 0.4% | Feb 20, 2026 | This vulnerability allows authenticated attackers to read an arbitrary file by changing a filepath parameter into an int... |
| CVE-2025-30416 | CRITICAL | 10 | 0.4% | Feb 20, 2026 | Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cy... |
| CVE-2025-30412 | CRITICAL | 10 | 0.6% | Feb 20, 2026 | Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis ... |
| CVE-2025-30411 | CRITICAL | 10 | 0.6% | Feb 20, 2026 | Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis ... |
| CVE-2025-30410 | CRITICAL | 9.8 | 0.6% | Feb 20, 2026 | Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis C... |
| CVE-2025-9208 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ W... |
| CVE-2025-8055 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Server-Side Request Forgery (SSRF) vulnerability in OpenText™ XM Fax allows Server Side Request Forgery. The vulnerabi... |
| CVE-2025-8054 | HIGH | 7.5 | 0.3% | Feb 19, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText™ XM Fax allows ... |
| CVE-2025-13672 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ W... |
| CVE-2025-13671 | MEDIUM | 6.5 | 0.1% | Feb 19, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in OpenText™ Web Site Management Server allows Cross Site Request Forger... |
| CVE-2025-67305 | CRITICAL | 9.8 | 0.5% | Feb 19, 2026 | In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These ... |
| CVE-2025-67304 | CRITICAL | 9.8 | 0.5% | Feb 19, 2026 | In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL ... |
| CVE-2025-69725 | MEDIUM | 4.7 | 0.2% | Feb 19, 2026 | An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect vi... |
| CVE-2025-69674 | MEDIUM | 6.4 | 0.2% | Feb 19, 2026 | Buffer Overflow vulnerability in CDATA FD614GS3-R850 V3.2.7_P161006 (Build.0333.250211) allows an attacker to execute ar... |
| CVE-2025-71250 | — | — | — | Feb 19, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-71249 | — | — | — | Feb 19, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now