2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62615 | CRITICAL | 9.8 | 0.4% | Feb 4, 2026 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut... |
| CVE-2025-13375 | CRITICAL | 9.8 | 0.5% | Feb 4, 2026 | IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user to execute arbitrary c... |
| CVE-2025-64712 | CRITICAL | 9.8 | 0.6% | Feb 4, 2026 | The unstructured library provides open-source components for ingesting and pre-processing images and text documents, suc... |
| CVE-2025-5329 | CRITICAL | 9.8 | 0.5% | Feb 4, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martcode Software ... |
| CVE-2025-59818 | CRITICAL | 9.8 | 0.5% | Feb 4, 2026 | This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file ... |
| CVE-2025-65078 | CRITICAL | 9.3 | 0.5% | Feb 3, 2026 | An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark device... |
| CVE-2025-62799 | CRITICAL | 9.8 | 0.5% | Feb 3, 2026 | Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). ... |
| CVE-2025-10878 | CRITICAL | 10 | 0.6% | Feb 3, 2026 | A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The... |
| CVE-2025-69983 | CRITICAL | 9.8 | 0.4% | Feb 3, 2026 | FUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly s... |
| CVE-2025-69981 | CRITICAL | 9.8 | 0.7% | Feb 3, 2026 | FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks aut... |
| CVE-2025-69971 | CRITICAL | 9.8 | 2.0% | Feb 3, 2026 | FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-code... |
| CVE-2025-69970 | CRITICAL | 9.3 | 0.5% | Feb 3, 2026 | FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' ... |
| CVE-2025-67188 | CRITICAL | 9.8 | 0.6% | Feb 3, 2026 | A buffer overflow vulnerability exists in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The issue resides in the setRadvdCfg ... |
| CVE-2025-67187 | CRITICAL | 9.8 | 0.4% | Feb 3, 2026 | A stack-based buffer overflow vulnerability was identified in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The flaw exists i... |
| CVE-2025-67186 | CRITICAL | 9.8 | 0.7% | Feb 3, 2026 | TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability in the setUrlFilterRules interface of /... |
| CVE-2025-65875 | CRITICAL | 9.8 | 0.4% | Feb 3, 2026 | An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 and earlier allows attackers to execute a... |
| CVE-2025-63624 | CRITICAL | 9.8 | 0.6% | Feb 3, 2026 | SQL Injection vulnerability in Shandong Kede Electronics Co., Ltd IoT smart water meter monitoring platform v.1.0 allows... |
| CVE-2025-61506 | CRITICAL | 9.8 | 0.6% | Feb 3, 2026 | An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of ... |
| CVE-2025-57529 | CRITICAL | 9.8 | 0.6% | Feb 3, 2026 | YouDataSum CPAS Audit Management System <=v4.9 is vulnerable to SQL Injection in /cpasList/findArchiveReportByDah due to... |
| CVE-2025-52626 | CRITICAL | 9.8 | 0.6% | Feb 3, 2026 | A Potential Command Injection vulnerability in HCL AION. An This can allow unintended command execution, potentially ... |
| CVE-2025-5319 | CRITICAL | 9.8 | 0.4% | Feb 3, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Emit Informatics a... |
| CVE-2025-67856 | CRITICAL | 9.8 | 0.3% | Feb 3, 2026 | A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awa... |
| CVE-2025-67484 | CRITICAL | 9.8 | 0.4% | Feb 3, 2026 | Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiFor... |
| CVE-2025-66480 | CRITICAL | 9.8 | 1.4% | Feb 2, 2026 | Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists ... |
| CVE-2025-8587 | CRITICAL | 9.8 | 0.3% | Feb 2, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AKCE Software Tech... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now