2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66698 | HIGH | 8.6 | 0.5% | Jan 13, 2026 | An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to var... |
| CVE-2025-65783 | CRITICAL | 9.8 | 0.5% | Jan 13, 2026 | An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.... |
| CVE-2025-12548 | CRITICAL | 9 | 1.2% | Jan 13, 2026 | A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command exe... |
| CVE-2025-55462 | MEDIUM | 6.5 | 0.4% | Jan 13, 2026 | A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header ... |
| CVE-2025-36640 | HIGH | 8.8 | 0.1% | Jan 13, 2026 | A vulnerability has been identified in the installation/uninstallation of the Nessus Agent Tray App on Windows Hosts whi... |
| CVE-2025-13447 | MEDIUM | 6.8 | 25.4% | Jan 13, 2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker ... |
| CVE-2025-13444 | MEDIUM | 6.8 | 25.4% | Jan 13, 2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker ... |
| CVE-2025-9435 | MEDIUM | 5.5 | 0.5% | Jan 13, 2026 | Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module |
| CVE-2025-9427 | HIGH | 8.4 | 0.3% | Jan 13, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Lemonsoft W... |
| CVE-2025-14507 | MEDIUM | 5.3 | 0.4% | Jan 13, 2026 | The EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Sensitive Information Expos... |
| CVE-2025-11669 | HIGH | 8.1 | 0.7% | Jan 13, 2026 | Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versi... |
| CVE-2025-11250 | CRITICAL | 9.1 | 1.4% | Jan 13, 2026 | Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper fi... |
| CVE-2025-13774 | HIGH | 8.8 | 0.4% | Jan 13, 2026 | A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.4 and 13.0.1 where an SQL injection vulnerability ... |
| CVE-2025-59022 | HIGH | 8.1 | 0.4% | Jan 13, 2026 | Backend users who had access to the recycler module could delete arbitrary data from any database table defined in the T... |
| CVE-2025-59021 | MEDIUM | 6.4 | 0.2% | Jan 13, 2026 | Backend users with access to the redirects module and write permission on the sys_redirect table were able to read, crea... |
| CVE-2025-59020 | MEDIUM | 6.5 | 0.3% | Jan 13, 2026 | By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO... |
| CVE-2025-14001 | MEDIUM | 5.4 | 0.2% | Jan 13, 2026 | The WP Duplicate Page plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability ... |
| CVE-2025-40944 | HIGH | 8.7 | 0.4% | Jan 13, 2026 | A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200M... |
| CVE-2025-40942 | HIGH | 7.8 | 0.1% | Jan 13, 2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected application contains... |
| CVE-2025-40805 | CRITICAL | 10 | 0.6% | Jan 13, 2026 | Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthe... |
| CVE-2025-41717 | HIGH | 8.8 | 0.5% | Jan 13, 2026 | An unauthenticated remote attacker can trick a high privileged user into uploading a malicious payload via the config-up... |
| CVE-2025-14829 | CRITICAL | 9.1 | 0.3% | Jan 13, 2026 | The E-xact | Hosted Payment | WordPress plugin through 2.0 is vulnerable to arbitrary file deletion due to insufficient ... |
| CVE-2025-10915 | CRITICAL | 9.8 | 0.3% | Jan 13, 2026 | The Dreamer Blog WordPress theme through 1.2 is vulnerable to arbitrary installations due to a missing capability check... |
| CVE-2025-66177 | HIGH | 8.8 | 0.3% | Jan 13, 2026 | There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models.... |
| CVE-2025-66176 | HIGH | 8.8 | 0.5% | Jan 13, 2026 | There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now