2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71201 | HIGH | 7.1 | 0.1% | Feb 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix early read unlock of page with EOF in mi... |
| CVE-2025-71200 | MEDIUM | 5.5 | 0.1% | Feb 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci-of-dwcmshc: Prevent illegal clock reduct... |
| CVE-2025-8572 | CRITICAL | 9.8 | 0.4% | Feb 14, 2026 | The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7... |
| CVE-2025-6792 | MEDIUM | 5.3 | 0.3% | Feb 14, 2026 | The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing c... |
| CVE-2025-15483 | MEDIUM | 4.4 | 0.2% | Feb 14, 2026 | The Link Hopper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hop_name’ parameter in all ve... |
| CVE-2025-14873 | MEDIUM | 4.3 | 0.1% | Feb 14, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Req... |
| CVE-2025-14852 | MEDIUM | 4.3 | 0.2% | Feb 14, 2026 | The MDirector Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2025-14608 | MEDIUM | 5.3 | 0.2% | Feb 14, 2026 | The WP Last Modified Info plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, ... |
| CVE-2025-14067 | MEDIUM | 5.3 | 0.2% | Feb 14, 2026 | The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability chec... |
| CVE-2025-13973 | MEDIUM | 5.3 | 0.3% | Feb 14, 2026 | The StickEasy Protected Contact Form plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versi... |
| CVE-2025-13681 | MEDIUM | 4.9 | 0.4% | Feb 14, 2026 | The BFG Tools – Extension Zipper plugin for WordPress is vulnerable to Path Traversal in all versions up to, and includi... |
| CVE-2025-70957 | HIGH | 7.5 | 0.3% | Feb 13, 2026 | A Denial of Service (DoS) vulnerability was discovered in the TON Lite Server before v2024.09. The vulnerability arises ... |
| CVE-2025-70956 | HIGH | 7.5 | 0.5% | Feb 13, 2026 | A State Pollution vulnerability was discovered in the TON Virtual Machine (TVM) before v2025.04. The issue exists in the... |
| CVE-2025-70955 | HIGH | 7.5 | 0.6% | Feb 13, 2026 | A Stack Overflow vulnerability was discovered in the TON Virtual Machine (TVM) before v2024.10. The vulnerability stems ... |
| CVE-2025-70954 | HIGH | 7.5 | 0.6% | Feb 13, 2026 | A Null Pointer Dereference vulnerability exists in the TON Virtual Machine (TVM) within the TON Blockchain before v2025.... |
| CVE-2025-70866 | HIGH | 8.8 | 0.4% | Feb 13, 2026 | LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User rol... |
| CVE-2025-69633 | CRITICAL | 9.8 | 0.4% | Feb 13, 2026 | A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through ... |
| CVE-2025-15157 | HIGH | 8.8 | 0.3% | Feb 13, 2026 | The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification... |
| CVE-2025-68128 | — | — | — | Feb 13, 2026 | Rejected reason: reserved but not needed |
| CVE-2025-68127 | — | — | — | Feb 13, 2026 | Rejected reason: reserved but not needed |
| CVE-2025-68126 | — | — | — | Feb 13, 2026 | Rejected reason: reserved but not needed |
| CVE-2025-68125 | — | — | — | Feb 13, 2026 | Rejected reason: reserved but not needed |
| CVE-2025-68124 | — | — | — | Feb 13, 2026 | Rejected reason: reserved but not needed |
| CVE-2025-58184 | — | — | — | Feb 13, 2026 | Rejected reason: reserved but not needed |
| CVE-2025-58182 | — | — | — | Feb 13, 2026 | Rejected reason: reserved but not needed |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now