2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12641 | MEDIUM | 6.5 | 0.4% | Jan 16, 2026 | The Awesome Support - WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to mis... |
| CVE-2025-62582 | CRITICAL | 9.8 | 0.5% | Jan 16, 2026 | Delta Electronics DIAView has multiple vulnerabilities. |
| CVE-2025-62581 | CRITICAL | 9.8 | 0.5% | Jan 16, 2026 | Delta Electronics DIAView has multiple vulnerabilities. |
| CVE-2025-65118 | CRITICAL | 9.3 | 0.3% | Jan 16, 2026 | The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimizatio... |
| CVE-2025-65117 | HIGH | 7.7 | 0.2% | Jan 16, 2026 | The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed O... |
| CVE-2025-64769 | HIGH | 7.6 | 0.2% | Jan 16, 2026 | The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted an... |
| CVE-2025-64729 | HIGH | 8.2 | 0.2% | Jan 16, 2026 | The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optim... |
| CVE-2025-64691 | CRITICAL | 9.3 | 0.3% | Jan 16, 2026 | The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scr... |
| CVE-2025-61943 | HIGH | 7.8 | 0.3% | Jan 16, 2026 | The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper ... |
| CVE-2025-61937 | CRITICAL | 10 | 1.5% | Jan 16, 2026 | The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS sys... |
| CVE-2025-14237 | CRITICAL | 9.8 | 0.9% | Jan 16, 2026 | Buffer overflow in XPS font parse processing on Small Office Multifunction Printers and Laser Printers(*) which may allo... |
| CVE-2025-14236 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Buffer overflow in Address Book attribute tag processing on Small Office Multifunction Printers(*) which may allow an at... |
| CVE-2025-14235 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Buffer overflow in XPS font fpgm data processing on Small Office Multifunction Printers and Laser Printers(*) which may ... |
| CVE-2025-14234 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Buffer overflow in CPCA list processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an ... |
| CVE-2025-14233 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may all... |
| CVE-2025-14232 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Buffer overflow in XML processing of XPS file in Small Office Multifunction Printers and Laser Printers(*) which may all... |
| CVE-2025-14231 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Buffer overflow in print job processing by WSD on Small Office Multifunction Printers and Laser Printers(*) which may al... |
| CVE-2025-68671 | MEDIUM | 4.8 | 0.2% | Jan 15, 2026 | lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not ... |
| CVE-2025-67823 | HIGH | 8.2 | 0.3% | Jan 15, 2026 | A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX thro... |
| CVE-2025-67822 | CRITICAL | 9.4 | 0.4% | Jan 15, 2026 | A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.... |
| CVE-2025-70893 | HIGH | 8.8 | 0.4% | Jan 15, 2026 | A time-based blind SQL Injection vulnerability exists in PHPGurukul Cyber Cafe Management System v1.0 within the adminpr... |
| CVE-2025-70892 | CRITICAL | 9.8 | 0.4% | Jan 15, 2026 | Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The a... |
| CVE-2025-70891 | MEDIUM | 6.1 | 0.2% | Jan 15, 2026 | A stored cross-site scripting (XSS) vulnerability exists in Phpgurukul Cyber Cafe Management System v1.0 within the user... |
| CVE-2025-70890 | MEDIUM | 6.1 | 0.2% | Jan 15, 2026 | A stored cross-site scripting (XSS) vulnerability exists in Cyber Cafe Management System v1.0. An authenticated attacker... |
| CVE-2025-67025 | MEDIUM | 6.1 | 0.3% | Jan 15, 2026 | Cross Site Scripting vulnerability in Anycomment anycomment.io 0.4.4 allows a remote attacker to execute arbitrary code ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now