2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10855 | HIGH | 7.5 | 0.4% | Jan 22, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Solvera Software Services Trade Inc. Teknoera allows E... |
| CVE-2025-67684 | HIGH | 7.2 | 0.7% | Jan 22, 2026 | Quick.Cart is vulnerable to Local File Inclusion and Path Traversal issues in the theme selection mechanism. Quick.Cart ... |
| CVE-2025-67683 | MEDIUM | 6.1 | 0.3% | Jan 22, 2026 | Quick.Cart is vulnerable to reflected XSS via the sSort parameter. An attacker can craft a malicious URL which, when ope... |
| CVE-2025-10024 | HIGH | 7.5 | 0.3% | Jan 22, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in EXERT Computer Technologies Software Ltd. Co. Educatio... |
| CVE-2025-4764 | HIGH | 8.8 | 0.4% | Jan 22, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aida Computer Info... |
| CVE-2025-4763 | MEDIUM | 6.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aida Comput... |
| CVE-2025-13335 | MEDIUM | 6.5 | 0.5% | Jan 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.4, 18.7 before 18.7.2, and 1... |
| CVE-2025-71176 | MEDIUM | 6.8 | 0.1% | Jan 22, 2026 | pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users... |
| CVE-2025-27380 | HIGH | 7.6 | 0.2% | Jan 22, 2026 | HTML injection in Project Release in Altium Enterprise Server (AES) 7.0.3 on all platforms allows an authenticated attac... |
| CVE-2025-27379 | MEDIUM | 4.6 | 0.2% | Jan 22, 2026 | A stored cross-site scripting (XSS) vulnerability in the BOM Viewer in Altium AES 7.0.3 allows an authenticated attacker... |
| CVE-2025-27378 | CRITICAL | 9.8 | 0.4% | Jan 22, 2026 | AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic f... |
| CVE-2025-27377 | MEDIUM | 5.3 | 0.2% | Jan 22, 2026 | Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capa... |
| CVE-2025-69285 | MEDIUM | 6.1 | 0.4% | Jan 21, 2026 | SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.5.0 contain a mi... |
| CVE-2025-69209 | MEDIUM | 6.9 | 0.1% | Jan 21, 2026 | ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in ... |
| CVE-2025-68141 | HIGH | 7.4 | 0.2% | Jan 21, 2026 | EVerest is an EV charging software stack. Prior to version 2025.10.0, during the deserialization of a `DC_ChargeLoopRes`... |
| CVE-2025-68140 | MEDIUM | 4.3 | 0.1% | Jan 21, 2026 | EVerest is an EV charging software stack. Prior to version 2025.9.0, once the validity of the received V2G message has b... |
| CVE-2025-68139 | MEDIUM | 4.3 | 0.1% | Jan 21, 2026 | EVerest is an EV charging software stack. In all versions up to and including 2025.12.1, the default value for `terminat... |
| CVE-2025-68138 | MEDIUM | 4.7 | 0.2% | Jan 21, 2026 | EVerest is an EV charging software stack, and EVerest libocpp is a C++ implementation of the Open Charge Point Protocol.... |
| CVE-2025-68137 | HIGH | 8.3 | 0.3% | Jan 21, 2026 | EVerest is an EV charging software stack. Prior to version 2025.10.0, an integer overflow occurring in `SdpPacket::parse... |
| CVE-2025-68136 | HIGH | 7.4 | 0.3% | Jan 21, 2026 | EVerest is an EV charging software stack. Prior to version 2025.10.0, once the module receives a SDP request, it creates... |
| CVE-2025-13465 | MEDIUM | 5.3 | 1.5% | Jan 21, 2026 | Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An atta... |
| CVE-2025-12781 | MEDIUM | 5.3 | 0.5% | Jan 21, 2026 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the... |
| CVE-2025-68135 | MEDIUM | 6.5 | 0.3% | Jan 21, 2026 | EVerest is an EV charging software stack. Prior to version 2025.10.0, C++ exceptions are not properly handled for and by... |
| CVE-2025-68134 | HIGH | 7.4 | 0.2% | Jan 21, 2026 | EVerest is an EV charging software stack. Prior to version 2025.10.0, the use of the `assert` function to handle errors ... |
| CVE-2025-68132 | MEDIUM | 4.6 | 0.2% | Jan 21, 2026 | EVerest is an EV charging software stack. Prior to version 2025.12.0, `is_message_crc_correct` in the DZG_GSH01 powermet... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now