2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15322 | MEDIUM | 4.3 | 0.2% | Jan 30, 2026 | Tanium addressed an improper access controls vulnerability in Tanium Server. |
| CVE-2025-15288 | MEDIUM | 4.3 | 0.2% | Jan 29, 2026 | Tanium addressed an improper access controls vulnerability in Interact. |
| CVE-2025-69929 | CRITICAL | 9.8 | 0.4% | Jan 29, 2026 | An issue in N3uron Web User Interface v.1.21.7-240207.1047 allows a remote attacker to escalate privileges via the passw... |
| CVE-2025-69604 | HIGH | 7.8 | 0.1% | Jan 29, 2026 | An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to in... |
| CVE-2025-69516 | HIGH | 8.8 | 2.1% | Jan 29, 2026 | A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactica... |
| CVE-2025-63658 | HIGH | 7.5 | 1.1% | Jan 29, 2026 | A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to... |
| CVE-2025-63657 | HIGH | 7.5 | 1.0% | Jan 29, 2026 | An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attacke... |
| CVE-2025-63656 | HIGH | 7.5 | 1.0% | Jan 29, 2026 | An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers ... |
| CVE-2025-63655 | HIGH | 7.5 | 7.4% | Jan 29, 2026 | A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows att... |
| CVE-2025-63653 | HIGH | 7.5 | 1.0% | Jan 29, 2026 | An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attacker... |
| CVE-2025-63652 | HIGH | 7.5 | 1.0% | Jan 29, 2026 | A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to ... |
| CVE-2025-63651 | HIGH | 7.5 | 0.9% | Jan 29, 2026 | A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers t... |
| CVE-2025-63650 | HIGH | 7.5 | 1.0% | Jan 29, 2026 | An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers t... |
| CVE-2025-63649 | HIGH | 7.5 | 1.0% | Jan 29, 2026 | An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commi... |
| CVE-2025-15550 | MEDIUM | 5.3 | 0.1% | Jan 29, 2026 | birkir prime <= 0.4.0.beta.0 contains a cross-site request forgery vulnerability in its GraphQL endpoint that allows att... |
| CVE-2025-15549 | MEDIUM | 4.8 | 0.2% | Jan 29, 2026 | FluentCMS 2026 contains a stored cross-site scripting vulnerability that allows authenticated administrators to upload S... |
| CVE-2025-69749 | MEDIUM | 6.1 | 0.2% | Jan 29, 2026 | Cross Site Scripting vulnerability in tale v.2.0.5 allows an attacker to execute arbitrary code. |
| CVE-2025-15548 | MEDIUM | 6.5 | 0.1% | Jan 29, 2026 | Some VX800v v1.0 web interface endpoints transmit sensitive information over unencrypted HTTP due to missing application... |
| CVE-2025-15543 | MEDIUM | 4.6 | 0.2% | Jan 29, 2026 | Improper link resolution in USB HTTP access path in VX800v v1.0 allows a crafted USB device to expose root filesystem co... |
| CVE-2025-15542 | MEDIUM | 5.3 | 0.3% | Jan 29, 2026 | Improper handling of exceptional conditions in VX800v v1.0 in SIP processing allows an attacker to flood the device with... |
| CVE-2025-15541 | MEDIUM | 6.3 | 0.3% | Jan 29, 2026 | Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic... |
| CVE-2025-13399 | HIGH | 8.8 | 0.2% | Jan 29, 2026 | A weakness in the web interface’s application layer encryption in VX800v v1.0 allows an adjacent attacker to brute force... |
| CVE-2025-45160 | MEDIUM | 5.4 | 0.2% | Jan 29, 2026 | A HTML injection vulnerability exists in the file upload functionality of Cacti <= 1.2.29. When a file with an invalid f... |
| CVE-2025-15545 | MEDIUM | 6.8 | 0.5% | Jan 29, 2026 | The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such... |
| CVE-2025-71011 | MEDIUM | 6.2 | 0.1% | Jan 29, 2026 | An input validation vulnerability in the flow.Tensor.new_empty/flow.Tensor.new_ones/flow.Tensor.new_zeros component of O... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now