2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48094 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Magic... |
| CVE-2025-47666 | HIGH | 7.1 | 0.3% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Image... |
| CVE-2025-47600 | MEDIUM | 5.3 | 0.3% | Jan 22, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in xtemos WoodMart woodmart ... |
| CVE-2025-47555 | LOW | 3.8 | 0.3% | Jan 22, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly ... |
| CVE-2025-47500 | MEDIUM | 5.9 | 0.3% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Intal Sta... |
| CVE-2025-47474 | HIGH | 8.1 | 0.6% | Jan 22, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32123 | HIGH | 7.1 | 0.3% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup HTML5... |
| CVE-2025-31413 | MEDIUM | 4.3 | 0.1% | Jan 22, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in bdthemes Element Pack Elementor Addons bdthemes-element-pack-lite all... |
| CVE-2025-27005 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup HTML5... |
| CVE-2025-69822 | HIGH | 7.4 | 0.3% | Jan 22, 2026 | An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive informati... |
| CVE-2025-69821 | HIGH | 7.4 | 0.4% | Jan 22, 2026 | An issue in Beat XP VEGA Smartwatch (Firmware Version - RB303ATV006229) allows an attacker to cause a denial of service ... |
| CVE-2025-69820 | MEDIUM | 6 | 0.9% | Jan 22, 2026 | Directory Traversal vulnerability in Beam beta9 v.0.1.521 allows a remote attacker to obtain sensitive information via t... |
| CVE-2025-69764 | CRITICAL | 9.8 | 1.0% | Jan 22, 2026 | Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handl... |
| CVE-2025-69612 | MEDIUM | 6.5 | 0.9% | Jan 22, 2026 | A path traversal vulnerability exists in TMS Management Console (version 6.3.7.27386.20250818) from TMS Global Software.... |
| CVE-2025-36588 | HIGH | 8.8 | 0.6% | Jan 22, 2026 | Dell Unisphere for PowerMax, version(s) 10.2.0.x, contain(s) an Improper Neutralization of Special Elements used in an S... |
| CVE-2025-32057 | MEDIUM | 6.5 | 0.3% | Jan 22, 2026 | The Infotainment ECU manufactured by Bosch which is installed in Nissan Leaf ZE1 – 2020 uses a Redbend service for over-... |
| CVE-2025-32056 | MEDIUM | 4 | 0.3% | Jan 22, 2026 | The anti-theft protection mechanism can be bypassed by attackers due to weak response generation algorithms for the head... |
| CVE-2025-65098 | HIGH | 7.4 | 0.3% | Jan 22, 2026 | Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows s... |
| CVE-2025-64097 | CRITICAL | 9.8 | 0.4% | Jan 22, 2026 | NervesHub is a web service that allows users to manage over-the-air (OTA) firmware updates of devices in the field. A vu... |
| CVE-2025-15523 | MEDIUM | 4.8 | 0.1% | Jan 22, 2026 | MacOS version of Inkscape bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permis... |
| CVE-2025-13928 | HIGH | 7.5 | 0.7% | Jan 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.6.4, 18.7 before 18.7.2, and 1... |
| CVE-2025-13927 | HIGH | 7.5 | 0.8% | Jan 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 1... |
| CVE-2025-12738 | LOW | 1.3 | 0.4% | Jan 22, 2026 | Neo4j Enterprise edition versions prior to 2025.11.2 and 5.26.17 are vulnerable to a potential information disclosure by... |
| CVE-2025-14295 | HIGH | 7 | 0.2% | Jan 22, 2026 | Storing Passwords in a Recoverable Format vulnerability in Automated Logic WebCTRL on Windows, Carrier i-Vu on Windows. ... |
| CVE-2025-10856 | HIGH | 8.1 | 0.3% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Solvera Software Services Trade Inc. Teknoera allows Fi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now