2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10915 | CRITICAL | 9.8 | 0.3% | Jan 13, 2026 | The Dreamer Blog WordPress theme through 1.2 is vulnerable to arbitrary installations due to a missing capability check... |
| CVE-2025-66177 | HIGH | 8.8 | 0.3% | Jan 13, 2026 | There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models.... |
| CVE-2025-66176 | HIGH | 8.8 | 0.5% | Jan 13, 2026 | There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products... |
| CVE-2025-15514 | HIGH | 7.5 | 0.7% | Jan 12, 2026 | Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal mod... |
| CVE-2025-67146 | CRITICAL | 9.4 | 0.6% | Jan 12, 2026 | Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1)... |
| CVE-2025-29329 | CRITICAL | 9.8 | 1.0% | Jan 12, 2026 | Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote ... |
| CVE-2025-12420 | CRITICAL | 9.8 | 45.5% | Jan 12, 2026 | A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersona... |
| CVE-2025-67147 | CRITICAL | 9.8 | 0.3% | Jan 12, 2026 | Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', a... |
| CVE-2025-66802 | CRITICAL | 9.8 | 0.8% | Jan 12, 2026 | Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receive... |
| CVE-2025-51567 | CRITICAL | 9.1 | 0.4% | Jan 12, 2026 | A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote a... |
| CVE-2025-14470 | — | — | — | Jan 12, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2025-68657 | MEDIUM | 6.4 | 0.1% | Jan 12, 2026 | Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, calls to hi... |
| CVE-2025-68656 | MEDIUM | 6.8 | 0.2% | Jan 12, 2026 | Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, usb_class_r... |
| CVE-2025-68471 | MEDIUM | 6.5 | 0.4% | Jan 12, 2026 | Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 ... |
| CVE-2025-68468 | MEDIUM | 6.5 | 0.3% | Jan 12, 2026 | Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 ... |
| CVE-2025-68276 | MEDIUM | 5.5 | 0.1% | Jan 12, 2026 | Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 ... |
| CVE-2025-68622 | MEDIUM | 6.8 | 0.2% | Jan 12, 2026 | Espressif ESP-IDF USB Host UVC Class Driver allows video streaming from USB cameras. Prior to 2.4.0, a vulnerability in ... |
| CVE-2025-68472 | CRITICAL | 9.1 | 19.2% | Jan 12, 2026 | MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenti... |
| CVE-2025-66689 | MEDIUM | 6.5 | 0.5% | Jan 12, 2026 | A path traversal vulnerability exists in Zen MCP Server before 9.8.2 that allows authenticated attackers to read arbitra... |
| CVE-2025-63314 | CRITICAL | 10 | 0.3% | Jan 12, 2026 | A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to a... |
| CVE-2025-46070 | CRITICAL | 9.8 | 0.4% | Jan 12, 2026 | An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe compon... |
| CVE-2025-46068 | HIGH | 8.8 | 0.5% | Jan 12, 2026 | An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism |
| CVE-2025-46067 | HIGH | 8.2 | 0.3% | Jan 12, 2026 | An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges and obtain sensitive information v... |
| CVE-2025-46066 | CRITICAL | 9.9 | 0.3% | Jan 12, 2026 | An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges |
| CVE-2025-71063 | HIGH | 7.5 | 0.1% | Jan 12, 2026 | Errands before 46.2.10 does not verify TLS certificates for CalDAV servers. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now