2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52024 | CRITICAL | 9.4 | 0.4% | Jan 23, 2026 | A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testin... |
| CVE-2025-52023 | MEDIUM | 5.3 | 0.4% | Jan 23, 2026 | A vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to t... |
| CVE-2025-52022 | MEDIUM | 5.3 | 0.4% | Jan 23, 2026 | A vulnerability in the PHP backend of gemsloyalty.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers ... |
| CVE-2025-67264 | HIGH | 7.8 | 0.9% | Jan 23, 2026 | An OS command injection vulnerability in the com.sprd.engineermode component in Doogee Note59, Note59 Pro, and Note59 Pr... |
| CVE-2025-70986 | HIGH | 7.5 | 0.4% | Jan 23, 2026 | Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access ... |
| CVE-2025-70985 | CRITICAL | 9.1 | 0.4% | Jan 23, 2026 | Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data... |
| CVE-2025-70983 | CRITICAL | 9.9 | 0.4% | Jan 23, 2026 | Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to ... |
| CVE-2025-14947 | MEDIUM | 6.5 | 0.4% | Jan 23, 2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca... |
| CVE-2025-71177 | MEDIUM | 5.4 | 0.2% | Jan 23, 2026 | LavaLite CMS versions up to and including 10.1.0 contain a stored cross-site scripting vulnerability in the package crea... |
| CVE-2025-67231 | MEDIUM | 5.9 | 0.3% | Jan 23, 2026 | A reflected cross-site scripting (XSS) vulnerability in ToDesktop Builder v0.33.1 allows attackers to execute arbitrary ... |
| CVE-2025-67230 | HIGH | 7.1 | 0.2% | Jan 23, 2026 | Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0.33.0 allows attackers with rendere... |
| CVE-2025-67229 | CRITICAL | 9.8 | 0.3% | Jan 23, 2026 | An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauth... |
| CVE-2025-71161 | MEDIUM | 5.5 | 0.2% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm-verity: disable recursive forward error correcti... |
| CVE-2025-71160 | MEDIUM | 5.5 | 0.2% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: avoid chain re-validation if ... |
| CVE-2025-71159 | HIGH | 7.8 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free warning in btrfs_get_or_c... |
| CVE-2025-71158 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: gpio: mpsse: ensure worker is torn down When an IR... |
| CVE-2025-69908 | HIGH | 7.5 | 0.4% | Jan 23, 2026 | An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged... |
| CVE-2025-67125 | MEDIUM | 4.4 | 0.2% | Jan 23, 2026 | A signed integer overflow in docopt.cpp v0.6.2 (LeafPattern::match in docopt_private.h) when merging occurrence counters... |
| CVE-2025-67124 | MEDIUM | 6.8 | 0.3% | Jan 23, 2026 | A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an atta... |
| CVE-2025-66720 | HIGH | 7.5 | 0.4% | Jan 23, 2026 | Null pointer dereference in free5gc pcf 1.4.0 in file internal/sbi/processor/ampolicy.go in function HandleDeletePolicie... |
| CVE-2025-66719 | CRITICAL | 9.1 | 0.3% | Jan 23, 2026 | An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck... |
| CVE-2025-71157 | HIGH | 7.8 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: always drop device refcount in ib_del_su... |
| CVE-2025-71156 | HIGH | 7.8 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: gve: defer interrupt enabling until NAPI registrati... |
| CVE-2025-71155 | HIGH | 7.8 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix gmap_helper_zap_one_page() again A ... |
| CVE-2025-71154 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix memory leak on usb_submit_ur... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now