2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70298 | HIGH | 8.2 | 0.4% | Jan 15, 2026 | GPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmx_parse_tags function. |
| CVE-2025-66417 | CRITICAL | 9.8 | 0.4% | Jan 15, 2026 | GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQ... |
| CVE-2025-66292 | HIGH | 8.1 | 0.6% | Jan 15, 2026 | DPanel is an open source server management panel written in Go. Prior to 1.9.2, DPanel has an arbitrary file deletion vu... |
| CVE-2025-62193 | CRITICAL | 9.8 | 1.2% | Jan 15, 2026 | Sites running NOAA PMEL Live Access Server (LAS) are vulnerable to remote code execution via specially crafted requests ... |
| CVE-2025-67246 | HIGH | 7.3 | 0.2% | Jan 15, 2026 | A local information disclosure vulnerability exists in the Ludashi driver before 5.1025 due to a lack of access control ... |
| CVE-2025-67079 | CRITICAL | 9.8 | 0.4% | Jan 15, 2026 | File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL eng... |
| CVE-2025-67078 | MEDIUM | 6.1 | 0.2% | Jan 15, 2026 | Cross site scripting (XSS) vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute arbitrary... |
| CVE-2025-67077 | HIGH | 8.8 | 0.4% | Jan 15, 2026 | File upload vulnerability in Omnispace Agora Project before 25.10 allowing authenticated, or under certain conditions al... |
| CVE-2025-67076 | HIGH | 7.5 | 0.8% | Jan 15, 2026 | Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read fil... |
| CVE-2025-64516 | HIGH | 7.5 | 0.3% | Jan 15, 2026 | GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GL... |
| CVE-2025-61973 | HIGH | 8.8 | 0.1% | Jan 15, 2026 | A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A... |
| CVE-2025-71019 | HIGH | 7.5 | 0.3% | Jan 15, 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the wanSpeed parameter of the sub_65B5C function. T... |
| CVE-2025-70744 | HIGH | 7.5 | 0.3% | Jan 15, 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the cloneType parameter of the sub_65B5C function. ... |
| CVE-2025-67084 | CRITICAL | 9.9 | 0.4% | Jan 15, 2026 | File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files int... |
| CVE-2025-67083 | MEDIUM | 5.3 | 0.6% | Jan 15, 2026 | Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the ... |
| CVE-2025-67082 | MEDIUM | 6.5 | 0.3% | Jan 15, 2026 | An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" para... |
| CVE-2025-67081 | MEDIUM | 4.9 | 0.2% | Jan 15, 2026 | An SQL injection vulnerability in Itflow through 25.06 has been identified in the "role_id" parameter when editing a pro... |
| CVE-2025-13859 | MEDIUM | 6.4 | 0.2% | Jan 15, 2026 | The AffiliateX – Amazon Affiliate Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to ... |
| CVE-2025-13062 | HIGH | 8.8 | 0.5% | Jan 15, 2026 | The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and includin... |
| CVE-2025-12895 | MEDIUM | 5.3 | 0.2% | Jan 15, 2026 | The Kalium 3 | Creative WordPress & WooCommerce Theme theme for WordPress is vulnerable to unauthorized email sending du... |
| CVE-2025-14457 | HIGH | 7.4 | 0.2% | Jan 15, 2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modificatio... |
| CVE-2025-14448 | MEDIUM | 5.4 | 0.2% | Jan 15, 2026 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Multiple Chec... |
| CVE-2025-14058 | LOW | 3.2 | 0.1% | Jan 14, 2026 | A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized us... |
| CVE-2025-13455 | HIGH | 7.8 | 0.1% | Jan 14, 2026 | A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass T... |
| CVE-2025-13454 | MEDIUM | 6.8 | 0.1% | Jan 14, 2026 | A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now