2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70314 | CRITICAL | 9.8 | 0.4% | Feb 12, 2026 | webfsd 1.21 is vulnerable to a Buffer Overflow via a crafted request. This is due to the filename variable |
| CVE-2025-67433 | HIGH | 7.5 | 0.4% | Feb 12, 2026 | A heap buffer overflow in the processRequest function of Open TFTP Server MultiThreaded v1.7 allows attackers to cause a... |
| CVE-2025-67432 | HIGH | 7.5 | 0.3% | Feb 12, 2026 | A stack overflow in the ZBarcode_Encode function of Monkeybread Software MBS DynaPDF Plugin v21.3.1.1 allows attackers t... |
| CVE-2025-70981 | CRITICAL | 9.8 | 0.3% | Feb 12, 2026 | CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds p... |
| CVE-2025-69807 | HIGH | 7.5 | 0.4% | Feb 12, 2026 | p2r3 Bareiron commit: 8e4d4020d is vulnerable to Buffer Overflow, which allows unauthenticated remote attackers to cause... |
| CVE-2025-69806 | HIGH | 7.5 | 0.3% | Feb 12, 2026 | p2r3 bareiron commit: 8e4d4020d contains an Out-of-bounds Read, which allows unauthenticated remote attackers to get rel... |
| CVE-2025-63421 | HIGH | 7.8 | 0.1% | Feb 12, 2026 | An issue in filosoft Comerc.32 Commercial Invoicing v.16.0.0.3 allows a local attacker to execute arbitrary code via the... |
| CVE-2025-54519 | HIGH | 7.3 | 0.1% | Feb 12, 2026 | A DLL hijacking vulnerability in Doc Nav could allow a local attacker to achieve privilege escalation, potentially resul... |
| CVE-2025-52533 | HIGH | 8.7 | 0.3% | Feb 12, 2026 | Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and ... |
| CVE-2025-61880 | HIGH | 8.8 | 0.6% | Feb 12, 2026 | In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution. |
| CVE-2025-61879 | HIGH | 7.7 | 0.3% | Feb 12, 2026 | In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mech... |
| CVE-2025-55210 | HIGH | 7.5 | 0.3% | Feb 12, 2026 | FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to 17.0.5 and 16.0.17, F... |
| CVE-2025-54756 | HIGH | 8.6 | 0.1% | Feb 12, 2026 | BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 use a default passwo... |
| CVE-2025-70886 | HIGH | 7.5 | 0.4% | Feb 12, 2026 | An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the ... |
| CVE-2025-69752 | MEDIUM | 4.3 | 0.2% | Feb 12, 2026 | An issue in the "My Details" user profile functionality of Ideagen Q-Pulse 7.1.0.32 allows an authenticated user to view... |
| CVE-2025-69634 | CRITICAL | 9 | 0.1% | Feb 12, 2026 | Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges ... |
| CVE-2025-56647 | MEDIUM | 6.5 | 0.2% | Feb 12, 2026 | npm @farmfe/core before 1.7.6 is Missing Origin Validation in WebSocket. The development (hot module reloading) server d... |
| CVE-2025-14014 | CRITICAL | 9.8 | 0.4% | Feb 12, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software H... |
| CVE-2025-13004 | MEDIUM | 6.3 | 0.3% | Feb 12, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce P... |
| CVE-2025-13002 | MEDIUM | 6.1 | 0.2% | Feb 12, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Farktor Sof... |
| CVE-2025-10969 | CRITICAL | 9.8 | 0.3% | Feb 12, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farktor Software E... |
| CVE-2025-15575 | MEDIUM | 5.3 | 0.1% | Feb 12, 2026 | The firmware update functionality does not verify the authenticity of the supplied firmware update files. This allows at... |
| CVE-2025-15574 | MEDIUM | 6.5 | 0.2% | Feb 12, 2026 | When connecting to the Solax Cloud MQTT server the username is the "registration number", which is the 10 character stri... |
| CVE-2025-15573 | CRITICAL | 9.4 | 0.2% | Feb 12, 2026 | The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in th... |
| CVE-2025-41117 | MEDIUM | 6.1 | 0.3% | Feb 12, 2026 | Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the b... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now