2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70560 | HIGH | 8.4 | 0.1% | Feb 3, 2026 | Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application us... |
| CVE-2025-70559 | MEDIUM | 6.5 | 0.2% | Feb 3, 2026 | pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The libra... |
| CVE-2025-70311 | MEDIUM | 6.5 | 0.2% | Feb 3, 2026 | JEEWMS 1.0 is vulnerable to SQL Injection. Attackers can inject malicious SQL statements through the id1 and id2 paramet... |
| CVE-2025-69983 | CRITICAL | 9.8 | 0.4% | Feb 3, 2026 | FUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly s... |
| CVE-2025-69981 | CRITICAL | 9.8 | 0.7% | Feb 3, 2026 | FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks aut... |
| CVE-2025-69971 | CRITICAL | 9.8 | 2.0% | Feb 3, 2026 | FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-code... |
| CVE-2025-69970 | CRITICAL | 9.3 | 0.5% | Feb 3, 2026 | FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' ... |
| CVE-2025-69875 | HIGH | 7.8 | 0.1% | Feb 3, 2026 | A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient val... |
| CVE-2025-69848 | MEDIUM | 5.4 | 0.3% | Feb 3, 2026 | NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scr... |
| CVE-2025-69431 | MEDIUM | 6.1 | 0.3% | Feb 3, 2026 | The ZSPACE Q2C NAS contains a vulnerability related to incorrect symbolic link following. Attackers can format a USB dri... |
| CVE-2025-69430 | MEDIUM | 6.1 | 0.3% | Feb 3, 2026 | An Incorrect Symlink Follow vulnerability exists in multiple Yottamaster NAS devices, including DM2 (version equal to or... |
| CVE-2025-69429 | MEDIUM | 6.1 | 0.3% | Feb 3, 2026 | The ORICO NAS CD3510 (version V1.9.12 and below) contains an Incorrect Symlink Follow vulnerability that could be exploi... |
| CVE-2025-67189 | MEDIUM | 6.5 | 0.4% | Feb 3, 2026 | A buffer overflow vulnerability exists in the setParentalRules interface of TOTOLINK A950RG V4.1.2cu.5204_B20210112. The... |
| CVE-2025-67188 | CRITICAL | 9.8 | 0.6% | Feb 3, 2026 | A buffer overflow vulnerability exists in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The issue resides in the setRadvdCfg ... |
| CVE-2025-67187 | CRITICAL | 9.8 | 0.4% | Feb 3, 2026 | A stack-based buffer overflow vulnerability was identified in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The flaw exists i... |
| CVE-2025-67186 | CRITICAL | 9.8 | 0.7% | Feb 3, 2026 | TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability in the setUrlFilterRules interface of /... |
| CVE-2025-66374 | HIGH | 7.8 | 0.2% | Feb 3, 2026 | CyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through po... |
| CVE-2025-65924 | MEDIUM | 4.1 | 0.2% | Feb 3, 2026 | ERPNext thru 15.88.1 does not sanitize or remove certain HTML tags specifically `<a>` hyperlinks in fields that are inte... |
| CVE-2025-65923 | MEDIUM | 5.4 | 0.2% | Feb 3, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability was discovered within the CSV import mechanism of ERPNext thru 15.88.1... |
| CVE-2025-65875 | CRITICAL | 9.8 | 0.4% | Feb 3, 2026 | An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 and earlier allows attackers to execute a... |
| CVE-2025-63624 | CRITICAL | 9.8 | 0.6% | Feb 3, 2026 | SQL Injection vulnerability in Shandong Kede Electronics Co., Ltd IoT smart water meter monitoring platform v.1.0 allows... |
| CVE-2025-63372 | MEDIUM | 4.3 | 0.4% | Feb 3, 2026 | Articentgroup Zip Rar Extractor Tool 1.345.93.0 is vulnerable to Directory Traversal. The vulnerability resides in the Z... |
| CVE-2025-62599 | HIGH | 7.5 | 0.4% | Feb 3, 2026 | eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management ... |
| CVE-2025-61506 | CRITICAL | 9.8 | 0.6% | Feb 3, 2026 | An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of ... |
| CVE-2025-60865 | HIGH | 7.8 | 0.1% | Feb 3, 2026 | Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate priv... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now