2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71149 | — | — | — | Jan 23, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-71148 | LOW | 3.3 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/handshake: restore destructor on submit failure... |
| CVE-2025-71147 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix a memory leak in tpm2_load_cmd ... |
| CVE-2025-71146 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: fix leaked ct in error pat... |
| CVE-2025-69907 | HIGH | 7.5 | 0.5% | Jan 23, 2026 | An unauthenticated information disclosure vulnerability exists in Newgen OmniDocs due to missing authentication and acce... |
| CVE-2025-71145 | HIGH | 7.8 | 0.2% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: phy: isp1301: fix non-OF device reference imba... |
| CVE-2025-13921 | MEDIUM | 4.3 | 0.3% | Jan 23, 2026 | The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to unau... |
| CVE-2025-4320 | CRITICAL | 10 | 0.5% | Jan 23, 2026 | Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Bire... |
| CVE-2025-4319 | CRITICAL | 9.4 | 0.4% | Jan 23, 2026 | Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulne... |
| CVE-2025-14866 | HIGH | 8.8 | 0.4% | Jan 23, 2026 | The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin... |
| CVE-2025-2204 | MEDIUM | 4.7 | 0.3% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tapandsign ... |
| CVE-2025-46699 | MEDIUM | 6.5 | 0.3% | Jan 23, 2026 | Dell Data Protection Advisor, versions prior to 19.12, contains an Improper Neutralization of Special Elements Used in a... |
| CVE-2025-14745 | MEDIUM | 6.4 | 0.2% | Jan 23, 2026 | The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Stored... |
| CVE-2025-14069 | MEDIUM | 6.4 | 0.2% | Jan 23, 2026 | The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sas... |
| CVE-2025-67847 | HIGH | 8.8 | 0.5% | Jan 23, 2026 | A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbi... |
| CVE-2025-3839 | HIGH | 8 | 0.4% | Jan 23, 2026 | A flaw was found in Epiphany, a tool that allows websites to open external URL handler applications with minimal user in... |
| CVE-2025-15522 | MEDIUM | 6.4 | 0.3% | Jan 23, 2026 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnera... |
| CVE-2025-15351 | HIGH | 7.8 | 0.3% | Jan 23, 2026 | Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerab... |
| CVE-2025-15350 | HIGH | 7.8 | 0.3% | Jan 23, 2026 | Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerab... |
| CVE-2025-15349 | HIGH | 7.5 | 0.4% | Jan 23, 2026 | Anritsu ShockLine SCPI Race Condition Remote Code Execution Vulnerability. This vulnerability allows network-adjacent at... |
| CVE-2025-15348 | HIGH | 7.8 | 0.3% | Jan 23, 2026 | Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerabi... |
| CVE-2025-15063 | CRITICAL | 9.8 | 2.1% | Jan 23, 2026 | Ollama MCP Server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote atta... |
| CVE-2025-15062 | HIGH | 7.8 | 0.3% | Jan 23, 2026 | Trimble SketchUp SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2025-15061 | CRITICAL | 9.8 | 2.1% | Jan 23, 2026 | Framelink Figma MCP Server fetchWithRetry Command Injection Remote Code Execution Vulnerability. This vulnerability allo... |
| CVE-2025-15059 | HIGH | 7.8 | 0.7% | Jan 23, 2026 | GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now