2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11002 | HIGH | 7.8 | 0.5% | Jan 23, 2026 | 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attacke... |
| CVE-2025-9290 | MEDIUM | 5.9 | 0.2% | Jan 23, 2026 | An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption d... |
| CVE-2025-67652 | MEDIUM | 6.1 | 0.1% | Jan 22, 2026 | An attacker with access to the project file could use the exposed credentials to impersonate users, escalate privileges... |
| CVE-2025-55705 | CRITICAL | 9.8 | 0.3% | Jan 22, 2026 | This vulnerability occurs when the system permits multiple simultaneous connections to the backend using the same charg... |
| CVE-2025-54816 | CRITICAL | 9.8 | 0.4% | Jan 22, 2026 | This vulnerability occurs when a WebSocket endpoint does not enforce proper authentication mechanisms, allowing unautho... |
| CVE-2025-53968 | HIGH | 7.5 | 0.4% | Jan 22, 2026 | This vulnerability arises because there are no limitations on the number of authentication attempts a user can make. An... |
| CVE-2025-25051 | MEDIUM | 6.1 | 0.1% | Jan 22, 2026 | An attacker could decrypt sensitive data, impersonate legitimate users or devices, and potentially gain access to netwo... |
| CVE-2025-9289 | MEDIUM | 4.7 | 0.2% | Jan 22, 2026 | A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sani... |
| CVE-2025-14751 | HIGH | 8.7 | 0.4% | Jan 22, 2026 | A low-privileged user can bypass account credentials without confirming the user's current authentication state, which m... |
| CVE-2025-14750 | HIGH | 8.7 | 0.3% | Jan 22, 2026 | The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally con... |
| CVE-2025-22234 | MEDIUM | 5.3 | 0.4% | Jan 22, 2026 | The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvi... |
| CVE-2025-68609 | MEDIUM | 6.6 | 0.4% | Jan 22, 2026 | A vulnerability in Palantir's Aries service allowed unauthenticated access to log viewing and management functionality o... |
| CVE-2025-66428 | HIGH | 8.8 | 0.4% | Jan 22, 2026 | An issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation. |
| CVE-2025-56590 | CRITICAL | 9.8 | 0.5% | Jan 22, 2026 | An issue was discovered in the InsertFromURL() function of the Apryse HTML2PDF SDK thru 11.10. This vulnerability could ... |
| CVE-2025-70899 | MEDIUM | 6.5 | 0.1% | Jan 22, 2026 | PHPgurukul Online Course Registration v3.1 lacks Cross-Site Request Forgery (CSRF) protection on all administrative form... |
| CVE-2025-69828 | CRITICAL | 10 | 0.5% | Jan 22, 2026 | File Upload vulnerability in TMS Global Software TMS Management Console v.6.3.7.27386.20250818 allows a remote attacker ... |
| CVE-2025-69321 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand S... |
| CVE-2025-69320 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand M... |
| CVE-2025-69319 | HIGH | 7.5 | 0.3% | Jan 22, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Beaver Builder Beaver Builder beaver-builder-... |
| CVE-2025-69318 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hossni Mubarak Job... |
| CVE-2025-69317 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scriptsbundle CarS... |
| CVE-2025-69316 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 TableOn... |
| CVE-2025-69315 | MEDIUM | 6.5 | 0.2% | Jan 22, 2026 | Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploit... |
| CVE-2025-69314 | HIGH | 8.1 | 0.4% | Jan 22, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-69313 | HIGH | 7.5 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in WPXPO PostX ultimate-post allows Exploiting Incorrectly Configured Access Control... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now