2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15570 | HIGH | 7.8 | 0.2% | Feb 10, 2026 | A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file strea... |
| CVE-2025-15569 | HIGH | 7.3 | 0.1% | Feb 10, 2026 | A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The impacted element is the function get_system_dpi of t... |
| CVE-2025-11537 | MEDIUM | 5 | 0.1% | Feb 10, 2026 | A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre... |
| CVE-2025-40587 | HIGH | 7.6 | 0.3% | Feb 10, 2026 | A vulnerability has been identified in Polarion V2404 (All versions < V2404.5), Polarion V2410 (All versions < V2410.2).... |
| CVE-2025-14895 | MEDIUM | 5.4 | 0.3% | Feb 10, 2026 | The PopupKit plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.0. Thi... |
| CVE-2025-11242 | CRITICAL | 9.8 | 0.3% | Feb 10, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Teknolist Computer Systems Software Publishing Industry and Trade In... |
| CVE-2025-12063 | MEDIUM | 5.7 | 0.2% | Feb 10, 2026 | An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the... |
| CVE-2025-13064 | MEDIUM | 4.5 | 0.2% | Feb 10, 2026 | A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script w... |
| CVE-2025-12757 | MEDIUM | 4.6 | 0.3% | Feb 10, 2026 | An AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are n... |
| CVE-2025-11547 | HIGH | 7.8 | 0.1% | Feb 10, 2026 | AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user. |
| CVE-2025-11142 | HIGH | 8.8 | 0.5% | Feb 10, 2026 | The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code executio... |
| CVE-2025-15314 | HIGH | 8.1 | 0.3% | Feb 10, 2026 | Tanium addressed an arbitrary file deletion vulnerability in end-user-cx. |
| CVE-2025-15313 | HIGH | 7.1 | 0.2% | Feb 10, 2026 | Tanium addressed an arbitrary file deletion vulnerability in Tanium EUSS. |
| CVE-2025-15310 | HIGH | 7.8 | 0.2% | Feb 10, 2026 | Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools. |
| CVE-2025-15147 | MEDIUM | 4.3 | 0.3% | Feb 10, 2026 | The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure... |
| CVE-2025-15319 | HIGH | 7.8 | 0.2% | Feb 9, 2026 | Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools. |
| CVE-2025-15318 | MEDIUM | 6 | 0.2% | Feb 9, 2026 | Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpoint Tools. |
| CVE-2025-15317 | MEDIUM | 6.5 | 0.3% | Feb 9, 2026 | Tanium addressed an uncontrolled resource consumption vulnerability in Tanium Server. |
| CVE-2025-15316 | HIGH | 7.8 | 0.1% | Feb 9, 2026 | Tanium addressed a local privilege escalation vulnerability in Tanium Server. |
| CVE-2025-15315 | HIGH | 7.8 | 0.1% | Feb 9, 2026 | Tanium addressed a local privilege escalation vulnerability in Tanium Module Server. |
| CVE-2025-14778 | MEDIUM | 5.4 | 0.3% | Feb 9, 2026 | A flaw was found in Keycloak. A significant Broken Access Control vulnerability exists in the UserManagedPermissionServi... |
| CVE-2025-7432 | LOW | 1 | 0.1% | Feb 9, 2026 | DPA countermeasures in Silicon Labs' Series 2 devices are not reseeded under certain conditions. This may allow an att... |
| CVE-2025-66630 | CRITICAL | 9.4 | 0.5% | Feb 9, 2026 | Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying c... |
| CVE-2025-63354 | MEDIUM | 4.8 | 0.2% | Feb 9, 2026 | Hitron HI3120 v7.2.4.5.2b1 allows stored XSS via the Parental Control option when creating a new filter. The device fail... |
| CVE-2025-59024 | MEDIUM | 6.5 | 0.1% | Feb 9, 2026 | Crafted delegations or IP fragments can poison cached delegations in Recursor. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now