2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62514 | HIGH | 7.1 | 0.3% | Jan 29, 2026 | Parsec is a cloud-based application for cryptographically secure file sharing. In versions on the 3.x branch prior to 3.... |
| CVE-2025-13905 | HIGH | 7 | 0.1% | Jan 29, 2026 | CWE-276: Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the reverse s... |
| CVE-2025-7714 | CRITICAL | 9.8 | 0.3% | Jan 29, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Global Interactive... |
| CVE-2025-7713 | MEDIUM | 6.1 | 0.2% | Jan 29, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Global Inte... |
| CVE-2025-71009 | MEDIUM | 6.2 | 0.1% | Jan 29, 2026 | An input validation vulnerability in the flow.scatter/flow.scatter_add component of OneFlow v0.9.0 allows attackers to c... |
| CVE-2025-71008 | MEDIUM | 6.2 | 0.1% | Jan 29, 2026 | A segmentation violation in the oneflow._oneflow_internal.autograd.Function.FunctionCtx.mark_non_differentiable componen... |
| CVE-2025-7014 | HIGH | 8.8 | 0.3% | Jan 29, 2026 | Session Fixation vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Session Hijacking. This issue affect... |
| CVE-2025-7013 | CRITICAL | 9.8 | 0.3% | Jan 29, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Explo... |
| CVE-2025-7016 | CRITICAL | 9.8 | 0.3% | Jan 29, 2026 | Improper Access Control vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Aut... |
| CVE-2025-7015 | CRITICAL | 9.8 | 0.2% | Jan 29, 2026 | Session Fixation vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Session Fi... |
| CVE-2025-14975 | HIGH | 8.1 | 0.3% | Jan 29, 2026 | The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a... |
| CVE-2025-55704 | MEDIUM | 6.9 | 0.2% | Jan 29, 2026 | Hidden functionality issue exists in multiple MFPs provided by Brother Industries, Ltd., which may allow an attacker to ... |
| CVE-2025-53869 | MEDIUM | 6.3 | 0.1% | Jan 29, 2026 | Multiple MFPs provided by Brother Industries, Ltd. does not properly validate server certificates, which may allow a man... |
| CVE-2025-15344 | HIGH | 8.8 | 0.3% | Jan 29, 2026 | Tanium addressed a SQL injection vulnerability in Asset. |
| CVE-2025-71007 | HIGH | 7.5 | 0.4% | Jan 28, 2026 | An input validation vulnerability in the oneflow.index_add component of OneFlow v0.9.0 allows attackers to cause a Denia... |
| CVE-2025-71006 | MEDIUM | 6.5 | 0.3% | Jan 28, 2026 | A floating point exception (FPE) in the oneflow.reshape component of OneFlow v0.9.0 allows attackers to cause a Denial o... |
| CVE-2025-71005 | MEDIUM | 6.5 | 0.2% | Jan 28, 2026 | A floating point exception (FPE) in the oneflow.view component of OneFlow v0.9.0 allows attackers to cause a Denial of S... |
| CVE-2025-71004 | MEDIUM | 6.5 | 0.2% | Jan 28, 2026 | A segmentation violation in the oneflow.logical_or component of OneFlow v0.9.0 allows attackers to cause a Denial of Ser... |
| CVE-2025-71003 | HIGH | 7.5 | 0.4% | Jan 28, 2026 | An input validation vulnerability in the flow.arange() component of OneFlow v0.9.0 allows attackers to cause a Denial of... |
| CVE-2025-71002 | MEDIUM | 6.5 | 0.3% | Jan 28, 2026 | A floating-point exception (FPE) in the flow.column_stack component of OneFlow v0.9.0 allows attackers to cause a Denial... |
| CVE-2025-69289 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | Discourse is an open source discussion platform. A privilege escalation vulnerability in versions prior to 3.5.4, 2025.1... |
| CVE-2025-69218 | MEDIUM | 6.5 | 0.2% | Jan 28, 2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderat... |
| CVE-2025-68934 | MEDIUM | 6.5 | 0.2% | Jan 28, 2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, authent... |
| CVE-2025-68933 | MEDIUM | 5.4 | 0.1% | Jan 28, 2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-adm... |
| CVE-2025-68666 | MEDIUM | 6.5 | 0.2% | Jan 28, 2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, users a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now