2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69766 | CRITICAL | 9.8 | 0.7% | Jan 21, 2026 | Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handl... |
| CVE-2025-69763 | CRITICAL | 9.8 | 0.8% | Jan 21, 2026 | Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memor... |
| CVE-2025-69762 | CRITICAL | 9.8 | 0.8% | Jan 21, 2026 | Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the list parameter, which can cause memory ... |
| CVE-2025-66960 | HIGH | 7.5 | 0.4% | Jan 21, 2026 | An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function rea... |
| CVE-2025-66959 | HIGH | 7.5 | 4.5% | Jan 21, 2026 | An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder |
| CVE-2025-70648 | HIGH | 7.5 | 0.3% | Jan 21, 2026 | Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security_5g parameter of the sub_727F4 function.... |
| CVE-2025-70646 | HIGH | 7.5 | 0.3% | Jan 21, 2026 | Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_72290 function. Th... |
| CVE-2025-70644 | HIGH | 7.5 | 0.3% | Jan 21, 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the time parameter of the sub_60CFC function. This ... |
| CVE-2025-57681 | MEDIUM | 5.4 | 0.2% | Jan 21, 2026 | The WorklogPRO - Timesheets for Jira plugin in Jira Data Center before version 4.23.6-jira10 and before version 4.23.5-j... |
| CVE-2025-70651 | HIGH | 7.5 | 0.3% | Jan 21, 2026 | Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow in the ssid parameter of the form_fast_setting_wifi_se... |
| CVE-2025-70650 | HIGH | 7.5 | 0.3% | Jan 21, 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the deviceList parameter of the formSetMacFilterCfg... |
| CVE-2025-70645 | HIGH | 7.5 | 0.3% | Jan 21, 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the deviceList parameter of the formSetWifiMacFilte... |
| CVE-2025-13878 | HIGH | 7.5 | 8.2% | Jan 21, 2026 | Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 thro... |
| CVE-2025-14083 | LOW | 2.7 | 0.3% | Jan 21, 2026 | A flaw was found in the Keycloak Admin REST API. This vulnerability allows the exposure of backend schema and rules, pot... |
| CVE-2025-14559 | MEDIUM | 6.5 | 0.4% | Jan 21, 2026 | A flaw was found in the keycloak-services component of Keycloak. This vulnerability allows the issuance of access and re... |
| CVE-2025-68133 | HIGH | 7.4 | 0.4% | Jan 21, 2026 | EVerest is an EV charging software stack. In versions 2025.9.0 and below, an attacker can exhaust the operating system's... |
| CVE-2025-15521 | CRITICAL | 9.8 | 0.4% | Jan 21, 2026 | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege e... |
| CVE-2025-58744 | HIGH | 7.5 | 0.1% | Jan 20, 2026 | Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in Milner ImageDirector Cap... |
| CVE-2025-58743 | HIGH | 7.5 | 0.1% | Jan 20, 2026 | Use of a Broken or Risky Cryptographic Algorithm (DES) vulnerability in the Password class in C2SConnections.dll in Mi... |
| CVE-2025-58742 | MEDIUM | 5.9 | 0.2% | Jan 20, 2026 | Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability ... |
| CVE-2025-58741 | HIGH | 7.5 | 0.2% | Jan 20, 2026 | Insufficiently Protected Credentials vulnerability in the Credential Field of Milner ImageDirector Capture allows retrie... |
| CVE-2025-58740 | MEDIUM | 5.5 | 0.1% | Jan 20, 2026 | The use of a hard-coded encryption key in calls to the Password function in C2SGlobalSettings.dll in Milner ImageDirecto... |
| CVE-2025-15367 | MEDIUM | 5.9 | 0.3% | Jan 20, 2026 | The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigati... |
| CVE-2025-15366 | MEDIUM | 5.9 | 0.4% | Jan 20, 2026 | The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigat... |
| CVE-2025-15282 | MEDIUM | 6 | 0.5% | Jan 20, 2026 | User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now