2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15578 | CRITICAL | 9.8 | 0.3% | Feb 16, 2026 | Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the sys... |
| CVE-2025-32058 | CRITICAL | 9.3 | 0.2% | Feb 15, 2026 | The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment... |
| CVE-2025-8572 | CRITICAL | 9.8 | 0.4% | Feb 14, 2026 | The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7... |
| CVE-2025-69633 | CRITICAL | 9.8 | 0.4% | Feb 13, 2026 | A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through ... |
| CVE-2025-69770 | CRITICAL | 10 | 0.6% | Feb 13, 2026 | A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execu... |
| CVE-2025-70314 | CRITICAL | 9.8 | 0.4% | Feb 12, 2026 | webfsd 1.21 is vulnerable to a Buffer Overflow via a crafted request. This is due to the filename variable |
| CVE-2025-70981 | CRITICAL | 9.8 | 0.3% | Feb 12, 2026 | CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds p... |
| CVE-2025-69634 | CRITICAL | 9 | 0.1% | Feb 12, 2026 | Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges ... |
| CVE-2025-14014 | CRITICAL | 9.8 | 0.4% | Feb 12, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software H... |
| CVE-2025-10969 | CRITICAL | 9.8 | 0.3% | Feb 12, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farktor Software E... |
| CVE-2025-15573 | CRITICAL | 9.4 | 0.2% | Feb 12, 2026 | The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in th... |
| CVE-2025-14892 | CRITICAL | 9.8 | 0.4% | Feb 12, 2026 | The Prime Listing Manager WordPress plugin through 1.1 allows an attacker to gain administrative access without having a... |
| CVE-2025-67135 | CRITICAL | 9.8 | 0.3% | Feb 11, 2026 | Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to compromise access contro... |
| CVE-2025-69872 | CRITICAL | 9.8 | 0.5% | Feb 11, 2026 | DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write acces... |
| CVE-2025-70085 | CRITICAL | 9.8 | 0.5% | Feb 11, 2026 | An issue was discovered in OpenSatKit 2.2.1. The EventErrStr buffer has a fixed size of 256 bytes. The code uses sprintf... |
| CVE-2025-69874 | CRITICAL | 9.8 | 0.8% | Feb 11, 2026 | nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers t... |
| CVE-2025-64075 | CRITICAL | 10 | 0.7% | Feb 11, 2026 | A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows ... |
| CVE-2025-12059 | CRITICAL | 9.8 | 0.3% | Feb 11, 2026 | Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry ... |
| CVE-2025-8668 | CRITICAL | 9.4 | 0.4% | Feb 11, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite So... |
| CVE-2025-8025 | CRITICAL | 9.8 | 0.5% | Feb 11, 2026 | Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinos... |
| CVE-2025-66277 | CRITICAL | 9.8 | 0.6% | Feb 11, 2026 | A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers ... |
| CVE-2025-7659 | CRITICAL | 9.1 | 0.2% | Feb 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 1... |
| CVE-2025-52436 | CRITICAL | 9.6 | 7.5% | Feb 10, 2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi... |
| CVE-2025-11242 | CRITICAL | 9.8 | 0.3% | Feb 10, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Teknolist Computer Systems Software Publishing Industry and Trade In... |
| CVE-2025-66630 | CRITICAL | 9.4 | 0.5% | Feb 9, 2026 | Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying c... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now