2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67858 | HIGH | 7 | 0.2% | Jan 8, 2026 | A Improper Neutralization of Argument Delimiters vulnerability in Foomuuri can lead to integrity loss of the firewall co... |
| CVE-2025-67091 | MEDIUM | 6.5 | 3.0% | Jan 8, 2026 | An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL.... |
| CVE-2025-67090 | MEDIUM | 5.1 | 0.2% | Jan 8, 2026 | The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL... |
| CVE-2025-67089 | HIGH | 8.1 | 1.4% | Jan 8, 2026 | A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present ... |
| CVE-2025-63611 | HIGH | 8.7 | 0.3% | Jan 8, 2026 | Cross-Site Scripting in phpgurukul Hostel Management System v2.1 user-provided complaint fields (Explain the Complaint) ... |
| CVE-2025-67603 | MEDIUM | 5.1 | 0.1% | Jan 8, 2026 | A Improper Authorization vulnerability in Foomuuri llows arbitrary users to influence the firewall configuration.This is... |
| CVE-2025-66003 | HIGH | 7.3 | 0.1% | Jan 8, 2026 | An External Control of File Name or Path vulnerability in smb4k allowsl ocal users to perform a local root exploit via s... |
| CVE-2025-66002 | MEDIUM | 6.9 | 0.1% | Jan 8, 2026 | An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability allows local users ... |
| CVE-2025-4596 | MEDIUM | 5.3 | 0.3% | Jan 8, 2026 | Asseco ADMX system is used for processing medical records. It allows logged in users to access medical files belonging t... |
| CVE-2025-8307 | MEDIUM | 5.9 | 0.1% | Jan 8, 2026 | Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sec... |
| CVE-2025-8306 | MEDIUM | 5.1 | 0.1% | Jan 8, 2026 | Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sec... |
| CVE-2025-14025 | HIGH | 8.5 | 0.4% | Jan 8, 2026 | A flaw was found in Ansible Automation Platform (AAP). Read-only scoped OAuth2 API Tokens in AAP, are enforced at the Ga... |
| CVE-2025-69260 | HIGH | 7.5 | 1.4% | Jan 8, 2026 | A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-... |
| CVE-2025-69259 | HIGH | 7.5 | 1.4% | Jan 8, 2026 | A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create ... |
| CVE-2025-69258 | CRITICAL | 9.8 | 3.2% | Jan 8, 2026 | A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an atta... |
| CVE-2025-62877 | CRITICAL | 9.8 | 0.5% | Jan 8, 2026 | Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password if they are... |
| CVE-2025-66001 | HIGH | 8.8 | 0.3% | Jan 8, 2026 | NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote... |
| CVE-2025-69169 | MEDIUM | 5.4 | 0.2% | Jan 8, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Noor Alam Easy Media Down... |
| CVE-2025-68892 | HIGH | 7.1 | 0.1% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus@hotmail.c... |
| CVE-2025-68891 | HIGH | 7.1 | 0.1% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Sutana WP App... |
| CVE-2025-68890 | HIGH | 7.1 | 0.1% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hands01 e-shops e-... |
| CVE-2025-68889 | HIGH | 7.1 | 0.2% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pinpoll Pinpoll pi... |
| CVE-2025-68887 | HIGH | 7.1 | 0.2% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CMSJunkie - WordPr... |
| CVE-2025-68875 | MEDIUM | 6.5 | 0.1% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jcaruso001 Flaming... |
| CVE-2025-68874 | HIGH | 7.1 | 0.1% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada Visitor S... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now