2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70029 | HIGH | 7.5 | 0.3% | Feb 11, 2026 | An issue in Sunbird-Ed SunbirdEd-portal v1.13.4 allows attackers to obtain sensitive information. The application disabl... |
| CVE-2025-69874 | CRITICAL | 9.8 | 0.8% | Feb 11, 2026 | nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers t... |
| CVE-2025-65480 | HIGH | 8.8 | 0.7% | Feb 11, 2026 | An issue was discovered in Pacom Unison Client 5.13.1. Authenticated users can inject malicious scripts in the Report Te... |
| CVE-2025-65128 | HIGH | 8.1 | 0.3% | Feb 11, 2026 | A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.... |
| CVE-2025-65127 | MEDIUM | 6.5 | 0.3% | Feb 11, 2026 | A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remot... |
| CVE-2025-13391 | MEDIUM | 5.8 | 0.2% | Feb 11, 2026 | The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerabl... |
| CVE-2025-64075 | CRITICAL | 10 | 0.7% | Feb 11, 2026 | A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows ... |
| CVE-2025-12474 | MEDIUM | 4.4 | 0.1% | Feb 11, 2026 | A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This ... |
| CVE-2025-61969 | HIGH | 7 | 0.1% | Feb 11, 2026 | Incorrect permission assignment in AMD µProf may allow a local user-privileged attacker to achieve privilege escalation,... |
| CVE-2025-52541 | HIGH | 7.3 | 0.1% | Feb 11, 2026 | A DLL hijacking vulnerability in Vivado could allow a local attacker to achieve privilege escalation, potentially result... |
| CVE-2025-48518 | MEDIUM | 6.9 | 0.1% | Feb 11, 2026 | Improper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially result... |
| CVE-2025-48508 | MEDIUM | 6 | 0.1% | Feb 11, 2026 | Improper Hardware reset flow logic in the GPU GFX Hardware IP block could allow a privileged attacker in a guest virtual... |
| CVE-2025-48503 | HIGH | 7.8 | 0.1% | Feb 11, 2026 | A DLL hijacking vulnerability in the AMD Software Installer could allow an attacker to achieve privilege escalation pote... |
| CVE-2025-12059 | CRITICAL | 9.8 | 0.3% | Feb 11, 2026 | Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry ... |
| CVE-2025-8668 | CRITICAL | 9.4 | 0.4% | Feb 11, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite So... |
| CVE-2025-8025 | CRITICAL | 9.8 | 0.5% | Feb 11, 2026 | Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinos... |
| CVE-2025-68406 | MEDIUM | 6.5 | 0.5% | Feb 11, 2026 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the... |
| CVE-2025-66278 | MEDIUM | 6.5 | 0.4% | Feb 11, 2026 | A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, th... |
| CVE-2025-66277 | CRITICAL | 9.8 | 0.6% | Feb 11, 2026 | A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers ... |
| CVE-2025-66274 | MEDIUM | 4.9 | 0.4% | Feb 11, 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote... |
| CVE-2025-62856 | MEDIUM | 4.4 | 0.3% | Feb 11, 2026 | A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator ac... |
| CVE-2025-62855 | MEDIUM | 4.4 | 0.3% | Feb 11, 2026 | A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator ac... |
| CVE-2025-62854 | MEDIUM | 6.5 | 0.5% | Feb 11, 2026 | An uncontrolled resource consumption vulnerability has been reported to affect File Station 5. If a remote attacker gain... |
| CVE-2025-62853 | MEDIUM | 6.5 | 0.6% | Feb 11, 2026 | A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, th... |
| CVE-2025-59386 | MEDIUM | 4.9 | 0.4% | Feb 11, 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now