2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62487 | LOW | 3.5 | 0.2% | Jan 9, 2026 | On October 1, 2025, Palantir discovered that images uploaded through the Dossier front-end app were not being marked cor... |
| CVE-2025-46299 | MEDIUM | 4.3 | 0.3% | Jan 9, 2026 | A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 ... |
| CVE-2025-46298 | MEDIUM | 6.5 | 0.3% | Jan 9, 2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, mac... |
| CVE-2025-46297 | MEDIUM | 5.5 | 0.1% | Jan 9, 2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.2. An app may be a... |
| CVE-2025-46286 | MEDIUM | 4.3 | 0.2% | Jan 9, 2026 | A logic issue was addressed with improved validation. This issue is fixed in iOS 26.2 and iPadOS 26.2. Restoring from a ... |
| CVE-2025-15500 | CRITICAL | 9.8 | 5.6% | Jan 9, 2026 | A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some un... |
| CVE-2025-15499 | CRITICAL | 9.8 | 5.3% | Jan 9, 2026 | A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability af... |
| CVE-2025-60538 | MEDIUM | 6.5 | 0.4% | Jan 9, 2026 | A lack of rate limiting in the login page of shiori v1.7.4 and below allows attackers to bypass authentication via a bru... |
| CVE-2025-51626 | MEDIUM | 6.5 | 0.2% | Jan 9, 2026 | SQL injection vulnerability in pss.sale.com 1.0 via the id parameter to the userfiles/php/cancel_order.php endpoint. |
| CVE-2025-67811 | MEDIUM | 6.5 | 0.3% | Jan 9, 2026 | Area9 Rhapsode 1.47.3 allows SQL Injection via multiple API endpoints accessible to authenticated users. Insufficient in... |
| CVE-2025-67810 | MEDIUM | 6.5 | 0.3% | Jan 9, 2026 | In Area9 Rhapsode 1.47.3, an authenticated attacker can exploit the operation, url, and filename parameters via POST req... |
| CVE-2025-66715 | MEDIUM | 6.5 | 0.2% | Jan 9, 2026 | A DLL hijacking vulnerability in Axtion ODISSAAS ODIS v1.8.4 allows attackers to execute arbitrary code via a crafted DL... |
| CVE-2025-67070 | HIGH | 8.2 | 0.3% | Jan 9, 2026 | A vulnerability exists in Intelbras CFTV IP NVD 9032 R Ftd V2.800.00IB00C.0.T, which allows an unauthenticated attacker ... |
| CVE-2025-70161 | CRITICAL | 9.8 | 24.1% | Jan 9, 2026 | EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passe... |
| CVE-2025-69542 | CRITICAL | 9.8 | 8.4% | Jan 9, 2026 | A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulner... |
| CVE-2025-69426 | CRITICAL | 10 | 0.4% | Jan 9, 2026 | The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating s... |
| CVE-2025-69425 | CRITICAL | 10 | 0.7% | Jan 9, 2026 | The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2... |
| CVE-2025-67004 | MEDIUM | 6.5 | 5.6% | Jan 9, 2026 | ** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via t... |
| CVE-2025-66744 | HIGH | 7.5 | 1.4% | Jan 9, 2026 | In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to... |
| CVE-2025-46645 | HIGH | 7.2 | 1.4% | Jan 9, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.... |
| CVE-2025-15496 | CRITICAL | 9.8 | 0.3% | Jan 9, 2026 | A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/... |
| CVE-2025-15495 | HIGH | 7.2 | 0.4% | Jan 9, 2026 | A vulnerability was found in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/editsite... |
| CVE-2025-15494 | HIGH | 8.8 | 0.4% | Jan 9, 2026 | A vulnerability has been found in RainyGao DocSys up to 2.02.37. This affects an unknown function of the file com/DocSys... |
| CVE-2025-15493 | CRITICAL | 9.8 | 0.4% | Jan 9, 2026 | A flaw has been found in RainyGao DocSys up to 2.02.36. The impacted element is an unknown function of the file src/com/... |
| CVE-2025-15035 | HIGH | 7.3 | 0.3% | Jan 9, 2026 | Improper Input Validation vulnerability in TP-Link Archer AXE75 v1.6 (vpn modules) allows an authenticated adjacent atta... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now