2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6830 | CRITICAL | 9.8 | 0.4% | Feb 9, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpoda Türkiye Info... |
| CVE-2025-66606 | CRITICAL | 9.6 | 0.2% | Feb 9, 2026 | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properl... |
| CVE-2025-66603 | CRITICAL | 9.8 | 0.3% | Feb 9, 2026 | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts the OP... |
| CVE-2025-66602 | CRITICAL | 9.8 | 0.3% | Feb 9, 2026 | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts access... |
| CVE-2025-15027 | CRITICAL | 9.8 | 0.4% | Feb 8, 2026 | The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including... |
| CVE-2025-64111 | CRITICAL | 9.8 | 1.2% | Feb 6, 2026 | Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-... |
| CVE-2025-68121 | CRITICAL | 10 | 0.8% | Feb 5, 2026 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th... |
| CVE-2025-68723 | CRITICAL | 9 | 0.3% | Feb 5, 2026 | Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin in... |
| CVE-2025-62616 | CRITICAL | 9.8 | 0.3% | Feb 4, 2026 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut... |
| CVE-2025-62615 | CRITICAL | 9.8 | 0.4% | Feb 4, 2026 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut... |
| CVE-2025-13375 | CRITICAL | 9.8 | 0.5% | Feb 4, 2026 | IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user to execute arbitrary c... |
| CVE-2025-64712 | CRITICAL | 9.8 | 0.6% | Feb 4, 2026 | The unstructured library provides open-source components for ingesting and pre-processing images and text documents, suc... |
| CVE-2025-5329 | CRITICAL | 9.8 | 0.5% | Feb 4, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martcode Software ... |
| CVE-2025-59818 | CRITICAL | 9.8 | 0.5% | Feb 4, 2026 | This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file ... |
| CVE-2025-65078 | CRITICAL | 9.3 | 0.5% | Feb 3, 2026 | An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark device... |
| CVE-2025-62799 | CRITICAL | 9.8 | 0.5% | Feb 3, 2026 | Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). ... |
| CVE-2025-10878 | CRITICAL | 10 | 0.6% | Feb 3, 2026 | A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The... |
| CVE-2025-69983 | CRITICAL | 9.8 | 0.4% | Feb 3, 2026 | FUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly s... |
| CVE-2025-69981 | CRITICAL | 9.8 | 0.7% | Feb 3, 2026 | FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks aut... |
| CVE-2025-69971 | CRITICAL | 9.8 | 2.0% | Feb 3, 2026 | FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-code... |
| CVE-2025-69970 | CRITICAL | 9.3 | 0.5% | Feb 3, 2026 | FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' ... |
| CVE-2025-67188 | CRITICAL | 9.8 | 0.6% | Feb 3, 2026 | A buffer overflow vulnerability exists in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The issue resides in the setRadvdCfg ... |
| CVE-2025-67187 | CRITICAL | 9.8 | 0.4% | Feb 3, 2026 | A stack-based buffer overflow vulnerability was identified in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The flaw exists i... |
| CVE-2025-67186 | CRITICAL | 9.8 | 0.7% | Feb 3, 2026 | TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability in the setUrlFilterRules interface of /... |
| CVE-2025-65875 | CRITICAL | 9.8 | 0.4% | Feb 3, 2026 | An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 and earlier allows attackers to execute a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now