2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69421 | HIGH | 7.5 | 0.8% | Jan 27, 2026 | Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i... |
| CVE-2025-69420 | HIGH | 7.5 | 0.8% | Jan 27, 2026 | Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE unio... |
| CVE-2025-69419 | HIGH | 7.4 | 0.4% | Jan 27, 2026 | Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16... |
| CVE-2025-69418 | MEDIUM | 4 | 0.1% | Jan 27, 2026 | Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs... |
| CVE-2025-68670 | CRITICAL | 9.8 | 1.3% | Jan 27, 2026 | xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerabi... |
| CVE-2025-68160 | MEDIUM | 4.7 | 0.2% | Jan 27, 2026 | Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO perf... |
| CVE-2025-66199 | MEDIUM | 5.9 | 0.4% | Jan 27, 2026 | Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decomp... |
| CVE-2025-55102 | HIGH | 7.5 | 0.4% | Jan 27, 2026 | A denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A special... |
| CVE-2025-55095 | HIGH | 7 | 0.1% | Jan 27, 2026 | The function _ux_host_class_storage_media_mount() is responsible for mounting partitions on a USB mass storage device. W... |
| CVE-2025-28164 | MEDIUM | 5.5 | 0.1% | Jan 27, 2026 | Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_creat... |
| CVE-2025-28162 | MEDIUM | 5.5 | 0.1% | Jan 27, 2026 | Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngim... |
| CVE-2025-15469 | MEDIUM | 5.5 | 0.2% | Jan 27, 2026 | Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing al... |
| CVE-2025-15468 | MEDIUM | 5.9 | 0.7% | Jan 27, 2026 | Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an un... |
| CVE-2025-15467 | HIGH | 8.8 | 47.6% | Jan 27, 2026 | Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigg... |
| CVE-2025-11187 | MEDIUM | 6.1 | 0.5% | Jan 27, 2026 | Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow... |
| CVE-2025-41728 | MEDIUM | 5.3 | 0.3% | Jan 27, 2026 | A low privileged remote attacker may be able to disclose confidential information from the memory of a privileged proces... |
| CVE-2025-41727 | HIGH | 7.8 | 0.2% | Jan 27, 2026 | A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to per... |
| CVE-2025-41726 | HIGH | 8.8 | 0.4% | Jan 27, 2026 | A low privileged remote attacker can execute arbitrary code by sending specially crafted calls to the web service of the... |
| CVE-2025-12387 | MEDIUM | 6.9 | 0.7% | Jan 27, 2026 | A vulnerability in the Pix-Link LV-WR21Q router's language module allows remote attackers to trigger a denial of service... |
| CVE-2025-12386 | MEDIUM | 6.9 | 0.7% | Jan 27, 2026 | Pix-Link LV-WR21Q does not enforce any form of authentication for endpoint /goform/getHomePageInfo. Remote unauthenticat... |
| CVE-2025-14971 | MEDIUM | 5.3 | 0.3% | Jan 27, 2026 | The Link Invoice Payment for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to ... |
| CVE-2025-30248 | HIGH | 8.9 | 0.6% | Jan 26, 2026 | DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker t... |
| CVE-2025-59473 | HIGH | 7.2 | 0.3% | Jan 26, 2026 | SQL Injection vulnerability in the Structure for Admin authenticated user |
| CVE-2025-59472 | HIGH | 7.5 | 0.4% | Jan 26, 2026 | A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in min... |
| CVE-2025-59471 | HIGH | 7.5 | 0.4% | Jan 26, 2026 | A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now