2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15514 | HIGH | 7.5 | 0.7% | Jan 12, 2026 | Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal mod... |
| CVE-2025-67146 | CRITICAL | 9.4 | 0.6% | Jan 12, 2026 | Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1)... |
| CVE-2025-29329 | CRITICAL | 9.8 | 1.0% | Jan 12, 2026 | Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote ... |
| CVE-2025-12420 | CRITICAL | 9.8 | 45.5% | Jan 12, 2026 | A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersona... |
| CVE-2025-67147 | CRITICAL | 9.8 | 0.3% | Jan 12, 2026 | Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', a... |
| CVE-2025-66802 | CRITICAL | 9.8 | 0.8% | Jan 12, 2026 | Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receive... |
| CVE-2025-51567 | CRITICAL | 9.1 | 0.4% | Jan 12, 2026 | A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote a... |
| CVE-2025-14470 | — | — | — | Jan 12, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2025-68657 | MEDIUM | 6.4 | 0.1% | Jan 12, 2026 | Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, calls to hi... |
| CVE-2025-68656 | MEDIUM | 6.8 | 0.2% | Jan 12, 2026 | Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, usb_class_r... |
| CVE-2025-68471 | MEDIUM | 6.5 | 0.4% | Jan 12, 2026 | Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 ... |
| CVE-2025-68468 | MEDIUM | 6.5 | 0.3% | Jan 12, 2026 | Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 ... |
| CVE-2025-68276 | MEDIUM | 5.5 | 0.1% | Jan 12, 2026 | Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 ... |
| CVE-2025-68622 | MEDIUM | 6.8 | 0.2% | Jan 12, 2026 | Espressif ESP-IDF USB Host UVC Class Driver allows video streaming from USB cameras. Prior to 2.4.0, a vulnerability in ... |
| CVE-2025-68472 | CRITICAL | 9.1 | 19.2% | Jan 12, 2026 | MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenti... |
| CVE-2025-66689 | MEDIUM | 6.5 | 0.5% | Jan 12, 2026 | A path traversal vulnerability exists in Zen MCP Server before 9.8.2 that allows authenticated attackers to read arbitra... |
| CVE-2025-63314 | CRITICAL | 10 | 0.3% | Jan 12, 2026 | A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to a... |
| CVE-2025-46070 | CRITICAL | 9.8 | 0.4% | Jan 12, 2026 | An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe compon... |
| CVE-2025-46068 | HIGH | 8.8 | 0.5% | Jan 12, 2026 | An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism |
| CVE-2025-46067 | HIGH | 8.2 | 0.3% | Jan 12, 2026 | An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges and obtain sensitive information v... |
| CVE-2025-46066 | CRITICAL | 9.9 | 0.3% | Jan 12, 2026 | An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges |
| CVE-2025-71063 | HIGH | 7.5 | 0.1% | Jan 12, 2026 | Errands before 46.2.10 does not verify TLS certificates for CalDAV servers. |
| CVE-2025-67813 | MEDIUM | 5.3 | 0.2% | Jan 12, 2026 | Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communica... |
| CVE-2025-66939 | MEDIUM | 5.4 | 0.2% | Jan 12, 2026 | Cross Site Scripting vulnerability in 66biolinks by AltumCode v.61.0.1 allows an attacker to execute arbitrary code via ... |
| CVE-2025-65553 | MEDIUM | 6.5 | 0.2% | Jan 12, 2026 | D3D Wi-Fi Home Security System ZX-G12 v2.1.17 is susceptible to RF jamming on the 433 MHz alarm sensor channel. An attac... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now