2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65368 | MEDIUM | 6.1 | 0.2% | Jan 15, 2026 | SparkyFitness v0.15.8.2 is vulnerable to Cross Site Scripting (XSS) via user input and LLM output. |
| CVE-2025-60011 | MEDIUM | 6.9 | 0.4% | Jan 15, 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Ne... |
| CVE-2025-60007 | MEDIUM | 6.8 | 0.1% | Jan 15, 2026 | A NULL Pointer Dereference vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS on MX, SRX and EX... |
| CVE-2025-60003 | HIGH | 8.7 | 0.4% | Jan 15, 2026 | A Buffer Over-read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved ... |
| CVE-2025-59961 | MEDIUM | 6.8 | 0.1% | Jan 15, 2026 | An Incorrect Permission Assignment for Critical Resource vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Ne... |
| CVE-2025-59960 | HIGH | 7.4 | 0.2% | Jan 15, 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (jdhcpd) of Juniper Ne... |
| CVE-2025-59959 | MEDIUM | 6.8 | 0.1% | Jan 15, 2026 | An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Jun... |
| CVE-2025-52987 | MEDIUM | 6.1 | 0.2% | Jan 15, 2026 | A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insig... |
| CVE-2025-65349 | MEDIUM | 5.4 | 0.2% | Jan 15, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability in Web management interface in Each Italy Wireless Mini Router WIRELES... |
| CVE-2025-15265 | MEDIUM | 6.1 | 0.3% | Jan 15, 2026 | An SSR XSS exists in async hydration when attacker‑controlled keys are passed to hydratable. The key is embedded inside ... |
| CVE-2025-70303 | MEDIUM | 5.5 | 0.2% | Jan 15, 2026 | A heap overflow in the uncv_parse_config() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) v... |
| CVE-2025-70302 | MEDIUM | 5.5 | 0.2% | Jan 15, 2026 | A heap overflow in the ghi_dmx_declare_opid_bin() function of GPAC v2.4.0 allows attackers to cause a Denial of Service ... |
| CVE-2025-67647 | CRITICAL | 9.1 | 0.5% | Jan 15, 2026 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, Svelt... |
| CVE-2025-13845 | HIGH | 7.8 | 0.3% | Jan 15, 2026 | CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious pro... |
| CVE-2025-13844 | MEDIUM | 5.3 | 0.1% | Jan 15, 2026 | CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious ... |
| CVE-2025-9014 | HIGH | 7.5 | 0.4% | Jan 15, 2026 | A Null Pointer Dereference vulnerability exists in the referer header check of the web portal of TP-Link TL-WR841N v14, ... |
| CVE-2025-70307 | HIGH | 7.5 | 0.4% | Jan 15, 2026 | A stack overflow in the dump_ttxt_sample function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via... |
| CVE-2025-70299 | MEDIUM | 6.5 | 0.3% | Jan 15, 2026 | A heap overflow in the avi_parse_input_file() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS... |
| CVE-2025-36911 | HIGH | 7.1 | 6.9% | Jan 15, 2026 | In key-based pairing, there is a possible ID due to a logic error in the code. This could lead to remote (proximal/adjac... |
| CVE-2025-70656 | HIGH | 7.5 | 0.3% | Jan 15, 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the mac parameter of the sub_65B5C function. This v... |
| CVE-2025-70310 | MEDIUM | 5.5 | 0.1% | Jan 15, 2026 | A heap overflow in the vorbis_to_intern() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) vi... |
| CVE-2025-70309 | MEDIUM | 5.5 | 0.1% | Jan 15, 2026 | A stack overflow in the pcmreframe_flush_packet function of GPAC v2.4.0 allows attackers to cause a Denial of Service (D... |
| CVE-2025-70308 | HIGH | 7.5 | 0.3% | Jan 15, 2026 | An out-of-bounds read in the GSF demuxer filter component of GPAC v2.4.0 allows attackers to cause a Denial of Service (... |
| CVE-2025-70305 | MEDIUM | 5.5 | 0.2% | Jan 15, 2026 | A stack overflow in the dmx_saf function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafte... |
| CVE-2025-70304 | HIGH | 7.5 | 0.3% | Jan 15, 2026 | A buffer overflow in the vobsub_get_subpic_duration() function of GPAC v2.4.0 allows attackers to cause a Denial of Serv... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now