2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12051 | HIGH | 7.8 | 0.2% | Jan 14, 2026 | The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-... |
| CVE-2025-12050 | HIGH | 7.8 | 0.2% | Jan 14, 2026 | The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-... |
| CVE-2025-68947 | MEDIUM | 5.7 | 0.1% | Jan 13, 2026 | NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by othe... |
| CVE-2025-68658 | MEDIUM | 4.8 | 0.2% | Jan 13, 2026 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram... |
| CVE-2025-37186 | HIGH | 7.8 | 0.2% | Jan 13, 2026 | A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking Virtual Intranet Access (VIA)... |
| CVE-2025-15056 | MEDIUM | 6.1 | 0.2% | Jan 13, 2026 | A lack of data validation vulnerability in the HTML export feature in Quill in allows Cross-Site Scripting (XSS). This ... |
| CVE-2025-68931 | HIGH | 7.5 | 0.2% | Jan 13, 2026 | Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding... |
| CVE-2025-68925 | MEDIUM | 5.3 | 0.1% | Jan 13, 2026 | Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the code doesn't val... |
| CVE-2025-68704 | HIGH | 7.5 | 0.2% | Jan 13, 2026 | Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.uti... |
| CVE-2025-68703 | HIGH | 7.5 | 0.1% | Jan 13, 2026 | Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the salt is derived ... |
| CVE-2025-68702 | HIGH | 7.5 | 0.1% | Jan 13, 2026 | Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses padLeft(... |
| CVE-2025-68701 | HIGH | 7.5 | 0.2% | Jan 13, 2026 | Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses determin... |
| CVE-2025-68698 | HIGH | 7.5 | 0.1% | Jan 13, 2026 | Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses PKCS1Enc... |
| CVE-2025-37179 | MEDIUM | 5.3 | 0.3% | Jan 13, 2026 | Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data ... |
| CVE-2025-37178 | HIGH | 7.5 | 0.3% | Jan 13, 2026 | Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data ... |
| CVE-2025-37177 | MEDIUM | 6.5 | 0.3% | Jan 13, 2026 | An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors runnin... |
| CVE-2025-37176 | HIGH | 7.2 | 1.2% | Jan 13, 2026 | A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject s... |
| CVE-2025-37175 | HIGH | 7.2 | 0.4% | Jan 13, 2026 | Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either A... |
| CVE-2025-37174 | HIGH | 7.2 | 0.5% | Jan 13, 2026 | Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors run... |
| CVE-2025-37173 | HIGH | 7.2 | 0.4% | Jan 13, 2026 | An improper input handling vulnerability exists in the web-based management interface of mobility conductors running eit... |
| CVE-2025-37172 | HIGH | 7.2 | 1.1% | Jan 13, 2026 | Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors runni... |
| CVE-2025-37171 | HIGH | 7.2 | 1.2% | Jan 13, 2026 | Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors runni... |
| CVE-2025-37170 | HIGH | 7.2 | 1.1% | Jan 13, 2026 | Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors runni... |
| CVE-2025-37169 | HIGH | 7.2 | 0.5% | Jan 13, 2026 | A stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gateway. Successful exp... |
| CVE-2025-37168 | CRITICAL | 9.1 | 0.4% | Jan 13, 2026 | Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 ope... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now