2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71248 | — | — | — | Feb 19, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-71247 | — | — | — | Feb 19, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-71246 | — | — | — | Feb 19, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-71245 | — | — | — | Feb 19, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-71244 | MEDIUM | 6.1 | 0.2% | Feb 19, 2026 | SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a m... |
| CVE-2025-71243 | CRITICAL | 9.8 | 5.1% | Feb 19, 2026 | The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Ex... |
| CVE-2025-71242 | MEDIUM | 6.5 | 0.2% | Feb 19, 2026 | SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does n... |
| CVE-2025-71241 | MEDIUM | 6.1 | 0.2% | Feb 19, 2026 | SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the private area. The content of the error me... |
| CVE-2025-71240 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | SPIP before 4.2.15 allows Cross-Site Scripting (XSS) via crafted content in HTML code tags. The application does not pro... |
| CVE-2025-55853 | CRITICAL | 9.1 | 0.4% | Feb 19, 2026 | SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not... |
| CVE-2025-9953 | CRITICAL | 9.8 | 0.3% | Feb 19, 2026 | Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd.... |
| CVE-2025-8350 | CRITICAL | 9.8 | 0.5% | Feb 19, 2026 | Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Intern... |
| CVE-2025-9062 | HIGH | 7.3 | 0.2% | Feb 19, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in MeCODE Informatics and Engineering Services Ltd. Envan... |
| CVE-2025-15563 | MEDIUM | 5.3 | 0.3% | Feb 19, 2026 | Any unauthenticated user can reset the WorkTime on-prem database configuration by sending a specific HTTP request to the... |
| CVE-2025-15562 | MEDIUM | 6.1 | 0.2% | Feb 19, 2026 | The server API endpoint /report/internet/urls reflects received data into the HTML response without applying proper enco... |
| CVE-2025-15561 | HIGH | 7.8 | 0.1% | Feb 19, 2026 | An attacker can exploit the update behavior of the WorkTime monitoring daemon to elevate privileges on the local system ... |
| CVE-2025-15560 | HIGH | 8.8 | 0.3% | Feb 19, 2026 | An authenticated attacker with minimal permissions can exploit a SQL injection in the WorkTime server "widget" API endpo... |
| CVE-2025-15559 | CRITICAL | 9.8 | 0.4% | Feb 19, 2026 | An unauthenticated attacker can inject OS commands when calling a server API endpoint in NesterSoft WorkTime. The server... |
| CVE-2025-13590 | HIGH | 7.2 | 0.7% | Feb 19, 2026 | A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the d... |
| CVE-2025-12107 | HIGH | 7.2 | 0.6% | Feb 19, 2026 | Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject a... |
| CVE-2025-41023 | MEDIUM | 6.9 | 0.4% | Feb 19, 2026 | An authentication bypass vulnerability has been found in Thesamur's AutoGPT. This vulnerability allows an attacker to by... |
| CVE-2025-40697 | MEDIUM | 5.1 | 0.4% | Feb 19, 2026 | Reflected Cross-Site Scripting (XSS) vulnerability in '/index.php' in Lewe WebMeasure, which allows remote attackers to ... |
| CVE-2025-4960 | HIGH | 7.8 | 0.1% | Feb 19, 2026 | The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege esca... |
| CVE-2025-4521 | HIGH | 8.8 | 0.3% | Feb 19, 2026 | The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escala... |
| CVE-2025-15586 | CRITICAL | 10 | 0.4% | Feb 19, 2026 | OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw whic... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now