2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69770 | CRITICAL | 10 | 0.6% | Feb 13, 2026 | A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execu... |
| CVE-2025-66676 | MEDIUM | 6.2 | 0.2% | Feb 13, 2026 | An issue in IObit Unlocker v1.3.0.11 allows attackers to cause a Denial of Service (DoS) via a crafted request. |
| CVE-2025-70123 | HIGH | 7.5 | 0.3% | Feb 13, 2026 | An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a ... |
| CVE-2025-70122 | HIGH | 7.5 | 0.3% | Feb 13, 2026 | A heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of... |
| CVE-2025-70121 | HIGH | 7.5 | 0.3% | Feb 13, 2026 | An array index out of bounds vulnerability in the AMF component of free5GC v4.0.1 allows remote attackers to cause a den... |
| CVE-2025-1790 | MEDIUM | 5.8 | 0.1% | Feb 13, 2026 | Local privilege escalation in Genetec Sipelia Plugin. An authenticated low-privileged Windows user could exploit this vu... |
| CVE-2025-70095 | MEDIUM | 6.5 | 0.2% | Feb 13, 2026 | A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 all... |
| CVE-2025-70094 | MEDIUM | 6.5 | 0.2% | Feb 13, 2026 | A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attacker... |
| CVE-2025-70093 | HIGH | 7.4 | 0.3% | Feb 13, 2026 | An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response. |
| CVE-2025-70091 | MEDIUM | 6.5 | 0.2% | Feb 13, 2026 | A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute... |
| CVE-2025-14349 | HIGH | 8.8 | 0.4% | Feb 13, 2026 | Privilege Defined With Unsafe Actions, Missing Authentication for Critical Function vulnerability in Universal Software ... |
| CVE-2025-33042 | HIGH | 7.3 | 0.6% | Feb 13, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific... |
| CVE-2025-48023 | MEDIUM | 6.5 | 0.2% | Feb 13, 2026 | A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ... |
| CVE-2025-48022 | MEDIUM | 6.5 | 0.2% | Feb 13, 2026 | A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ... |
| CVE-2025-48021 | MEDIUM | 6.5 | 0.2% | Feb 13, 2026 | A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ... |
| CVE-2025-15520 | MEDIUM | 4.3 | 0.2% | Feb 13, 2026 | The RegistrationMagic WordPress plugin before 6.0.7.2 checks nonces but not capabilities, allowing for the disclosure o... |
| CVE-2025-48020 | MEDIUM | 6.5 | 0.2% | Feb 13, 2026 | A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ... |
| CVE-2025-48019 | MEDIUM | 6.5 | 0.2% | Feb 13, 2026 | A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ... |
| CVE-2025-1924 | HIGH | 8.2 | 0.2% | Feb 13, 2026 | A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ... |
| CVE-2025-9293 | HIGH | 8.1 | 0.2% | Feb 13, 2026 | A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated s... |
| CVE-2025-9292 | HIGH | 7.5 | 0.3% | Feb 13, 2026 | A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed u... |
| CVE-2025-40905 | HIGH | 7.3 | 0.3% | Feb 13, 2026 | WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptograp... |
| CVE-2025-70092 | MEDIUM | 5.5 | 0.2% | Feb 12, 2026 | A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute... |
| CVE-2025-70845 | MEDIUM | 6.1 | 0.2% | Feb 12, 2026 | lty628 aidigu v1.9.1 is vulnerable to Cross Site Scripting (XSS) exists in the /setting/ page where the "intro" field is... |
| CVE-2025-14282 | MEDIUM | 5.4 | 0.4% | Feb 12, 2026 | A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now