2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9820 | MEDIUM | 4 | 0.2% | Jan 26, 2026 | A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 tok... |
| CVE-2025-9615 | LOW | 3.3 | 0.2% | Jan 26, 2026 | A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. Ne... |
| CVE-2025-9522 | MEDIUM | 5.3 | 0.2% | Jan 26, 2026 | Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests t... |
| CVE-2025-9521 | MEDIUM | 6.5 | 0.3% | Jan 26, 2026 | Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypa... |
| CVE-2025-9520 | MEDIUM | 6.8 | 0.4% | Jan 26, 2026 | An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate r... |
| CVE-2025-14969 | MEDIUM | 4.3 | 0.4% | Jan 26, 2026 | A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client... |
| CVE-2025-14525 | MEDIUM | 6.4 | 0.3% | Jan 26, 2026 | A flaw was found in kubevirt. A user within a virtual machine (VM), if the guest agent is active, can exploit this by ca... |
| CVE-2025-14459 | HIGH | 8.5 | 0.4% | Jan 26, 2026 | A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolu... |
| CVE-2025-11687 | MEDIUM | 6.1 | 0.3% | Jan 26, 2026 | A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page —... |
| CVE-2025-11065 | MEDIUM | 5.3 | 0.4% | Jan 26, 2026 | A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode... |
| CVE-2025-70368 | MEDIUM | 5.4 | 0.2% | Jan 26, 2026 | Worklenz version 2.1.5 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Project Updates feature. An att... |
| CVE-2025-14756 | HIGH | 8.8 | 2.7% | Jan 26, 2026 | Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing... |
| CVE-2025-71178 | HIGH | 7.1 | 0.2% | Jan 26, 2026 | Crucial Storage Executive installer versions prior to 11.08.082025.00 contain a DLL preloading vulnerability. During ins... |
| CVE-2025-57785 | MEDIUM | 6.5 | 0.3% | Jan 26, 2026 | A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which allows an unauthenticate... |
| CVE-2025-57784 | LOW | 3.3 | 0.1% | Jan 26, 2026 | Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows... |
| CVE-2025-57783 | MEDIUM | 5.3 | 0.4% | Jan 26, 2026 | Improper header parsing may lead to request smuggling has been identified in Hiawatha webserver version 11.7 which allow... |
| CVE-2025-70982 | CRITICAL | 9.9 | 0.3% | Jan 26, 2026 | Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to ... |
| CVE-2025-67274 | HIGH | 7.5 | 0.4% | Jan 26, 2026 | An issue in continuous.software aangine v.2025.2 allows a remote attacker to obtain sensitive information via the excel-... |
| CVE-2025-50537 | MEDIUM | 5.5 | 0.2% | Jan 26, 2026 | Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/sha... |
| CVE-2025-59109 | MEDIUM | 5.1 | 0.5% | Jan 26, 2026 | The dormakaba registration units 9002 (PIN Pad Units) have an exposed UART header on the backside. The PIN pad is sendin... |
| CVE-2025-59108 | CRITICAL | 9.2 | 0.4% | Jan 26, 2026 | By default, the password for the Access Manager's web interface, is set to 'admin'. In the tested version changing the p... |
| CVE-2025-59107 | HIGH | 8.5 | 0.2% | Jan 26, 2026 | Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The... |
| CVE-2025-59106 | HIGH | 8.8 | 0.7% | Jan 26, 2026 | The binary serving the web server and executing basically all actions launched from the Web UI is running with root priv... |
| CVE-2025-59105 | HIGH | 7 | 0.1% | Jan 26, 2026 | With physical access to the device and enough time an attacker can desolder the flash memory, modify it and then reinsta... |
| CVE-2025-59104 | HIGH | 7 | 0.2% | Jan 26, 2026 | With physical access to the device and enough time an attacker is able to solder test leads to the debug footprint (or u... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now