2025 CVE Vulnerabilities
45,323 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26385 | CRITICAL | 9.5 | 1.4% | Jan 30, 2026 | Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Com... |
| CVE-2025-1395 | HIGH | 8.2 | 0.3% | Jan 30, 2026 | Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technolog... |
| CVE-2025-12899 | MEDIUM | 6.5 | 0.3% | Jan 30, 2026 | A flaw in Zephyr’s network stack allows an IPv4 packet containing ICMP type 128 to be misclassified as an ICMPv6 Echo Re... |
| CVE-2025-15322 | MEDIUM | 4.3 | 0.2% | Jan 30, 2026 | Tanium addressed an improper access controls vulnerability in Tanium Server. |
| CVE-2025-15288 | MEDIUM | 4.3 | 0.2% | Jan 29, 2026 | Tanium addressed an improper access controls vulnerability in Interact. |
| CVE-2025-69929 | CRITICAL | 9.8 | 0.4% | Jan 29, 2026 | An issue in N3uron Web User Interface v.1.21.7-240207.1047 allows a remote attacker to escalate privileges via the passw... |
| CVE-2025-69604 | HIGH | 7.8 | 0.1% | Jan 29, 2026 | An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to in... |
| CVE-2025-69516 | HIGH | 8.8 | 2.1% | Jan 29, 2026 | A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactica... |
| CVE-2025-63658 | HIGH | 7.5 | 1.1% | Jan 29, 2026 | A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to... |
| CVE-2025-63657 | HIGH | 7.5 | 1.0% | Jan 29, 2026 | An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attacke... |
| CVE-2025-63656 | HIGH | 7.5 | 1.0% | Jan 29, 2026 | An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers ... |
| CVE-2025-63655 | HIGH | 7.5 | 7.4% | Jan 29, 2026 | A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows att... |
| CVE-2025-63653 | HIGH | 7.5 | 1.0% | Jan 29, 2026 | An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attacker... |
| CVE-2025-63652 | HIGH | 7.5 | 1.0% | Jan 29, 2026 | A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to ... |
| CVE-2025-63651 | HIGH | 7.5 | 0.9% | Jan 29, 2026 | A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers t... |
| CVE-2025-63650 | HIGH | 7.5 | 1.0% | Jan 29, 2026 | An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers t... |
| CVE-2025-63649 | HIGH | 7.5 | 1.0% | Jan 29, 2026 | An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commi... |
| CVE-2025-15550 | MEDIUM | 5.3 | 0.1% | Jan 29, 2026 | birkir prime <= 0.4.0.beta.0 contains a cross-site request forgery vulnerability in its GraphQL endpoint that allows att... |
| CVE-2025-15549 | MEDIUM | 4.8 | 0.2% | Jan 29, 2026 | FluentCMS 2026 contains a stored cross-site scripting vulnerability that allows authenticated administrators to upload S... |
| CVE-2025-69749 | MEDIUM | 6.1 | 0.2% | Jan 29, 2026 | Cross Site Scripting vulnerability in tale v.2.0.5 allows an attacker to execute arbitrary code. |
| CVE-2025-15548 | MEDIUM | 6.5 | 0.1% | Jan 29, 2026 | Some VX800v v1.0 web interface endpoints transmit sensitive information over unencrypted HTTP due to missing application... |
| CVE-2025-15543 | MEDIUM | 4.6 | 0.2% | Jan 29, 2026 | Improper link resolution in USB HTTP access path in VX800v v1.0 allows a crafted USB device to expose root filesystem co... |
| CVE-2025-15542 | MEDIUM | 5.3 | 0.3% | Jan 29, 2026 | Improper handling of exceptional conditions in VX800v v1.0 in SIP processing allows an attacker to flood the device with... |
| CVE-2025-15541 | MEDIUM | 6.3 | 0.3% | Jan 29, 2026 | Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic... |
| CVE-2025-13399 | HIGH | 8.8 | 0.2% | Jan 29, 2026 | A weakness in the web interface’s application layer encryption in VX800v v1.0 allows an adjacent attacker to brute force... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now