2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70746 | HIGH | 7.5 | 0.4% | Jan 16, 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the timeZone parameter of the fromSetSysTime functi... |
| CVE-2025-29943 | MEDIUM | 4.6 | 0.2% | Jan 16, 2026 | Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU ... |
| CVE-2025-68921 | HIGH | 7.8 | 0.3% | Jan 16, 2026 | SteelSeries Nahimic 3 1.10.7 allows Directory traversal. |
| CVE-2025-15104 | MEDIUM | 5.3 | 0.4% | Jan 16, 2026 | Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arb... |
| CVE-2025-14894 | CRITICAL | 9.8 | 0.6% | Jan 16, 2026 | Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not p... |
| CVE-2025-14510 | CRITICAL | 9.2 | 0.4% | Jan 16, 2026 | Incorrect Implementation of Authentication Algorithm vulnerability in ABB ABB Ability OPTIMAX.This issue affects ABB Abi... |
| CVE-2025-14435 | MEDIUM | 6.5 | 0.3% | Jan 16, 2026 | Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite re-renders on API er... |
| CVE-2025-68675 | HIGH | 7.5 | 2.0% | Jan 16, 2026 | In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy U... |
| CVE-2025-68438 | HIGH | 7.5 | 0.6% | Jan 16, 2026 | In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length... |
| CVE-2025-59870 | CRITICAL | 9.8 | 0.2% | Jan 16, 2026 | HCL MyXalytics is affected by improper management of a static JWT signing secret in the web application, where the secr... |
| CVE-2025-14844 | HIGH | 7.5 | 0.4% | Jan 16, 2026 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up... |
| CVE-2025-60021 | CRITICAL | 9.8 | 26.2% | Jan 16, 2026 | Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all ... |
| CVE-2025-14822 | MEDIUM | 6.5 | 0.3% | Jan 16, 2026 | Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authentica... |
| CVE-2025-14757 | MEDIUM | 5.3 | 0.3% | Jan 16, 2026 | The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Payment Status Bypass in all versions ... |
| CVE-2025-12007 | HIGH | 8.4 | 0.1% | Jan 16, 2026 | There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can up... |
| CVE-2025-12006 | HIGH | 7.2 | 0.3% | Jan 16, 2026 | There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW-F . An attacker can up... |
| CVE-2025-14375 | MEDIUM | 6.1 | 0.2% | Jan 16, 2026 | The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Reflec... |
| CVE-2025-14853 | MEDIUM | 4.3 | 0.1% | Jan 16, 2026 | The LEAV Last Email Address Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions <= 1.... |
| CVE-2025-14793 | MEDIUM | 5 | 0.2% | Jan 16, 2026 | The DK PDF – WordPress PDF Generator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions u... |
| CVE-2025-15527 | MEDIUM | 4.3 | 0.3% | Jan 16, 2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 10.2.2 ... |
| CVE-2025-15526 | MEDIUM | 5.3 | 0.3% | Jan 16, 2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and includi... |
| CVE-2025-15370 | MEDIUM | 4.3 | 0.2% | Jan 16, 2026 | The Shield: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to Insecure D... |
| CVE-2025-14982 | MEDIUM | 4.3 | 0.3% | Jan 16, 2026 | The Booking Calendar plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Exposu... |
| CVE-2025-14384 | MEDIUM | 4.3 | 0.2% | Jan 16, 2026 | The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to ... |
| CVE-2025-12957 | HIGH | 8.8 | 0.6% | Jan 16, 2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and incl... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now