2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67813 | MEDIUM | 5.3 | 0.2% | Jan 12, 2026 | Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communica... |
| CVE-2025-66939 | MEDIUM | 5.4 | 0.2% | Jan 12, 2026 | Cross Site Scripting vulnerability in 66biolinks by AltumCode v.61.0.1 allows an attacker to execute arbitrary code via ... |
| CVE-2025-65553 | MEDIUM | 6.5 | 0.2% | Jan 12, 2026 | D3D Wi-Fi Home Security System ZX-G12 v2.1.17 is susceptible to RF jamming on the 433 MHz alarm sensor channel. An attac... |
| CVE-2025-65552 | CRITICAL | 9.8 | 0.4% | Jan 12, 2026 | D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication chan... |
| CVE-2025-41078 | HIGH | 8.1 | 0.2% | Jan 12, 2026 | Weaknesses in the authorization mechanisms of Viafirma Documents v3.7.129 allow an authenticated user without privileges... |
| CVE-2025-41077 | HIGH | 8.1 | 0.2% | Jan 12, 2026 | IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the... |
| CVE-2025-41006 | CRITICAL | 9.3 | 0.3% | Jan 12, 2026 | Imaster's MEMS Events CRM contains an SQL injection vulnerability in ‘phone’ parameter in ‘/memsdemo/login.php’. |
| CVE-2025-41005 | HIGH | 8.7 | 0.3% | Jan 12, 2026 | Imaster's MEMS Events CRM contains an SQL injection vulnerability in‘keyword’ parameter in ‘/memsdemo/exchange_offers.ph... |
| CVE-2025-41004 | HIGH | 8.7 | 0.3% | Jan 12, 2026 | Imaster's Patient Records Management System is vulnerable to SQL Injection in the endpoint ‘/projects/hospital/admin/com... |
| CVE-2025-41003 | MEDIUM | 5.1 | 0.3% | Jan 12, 2026 | Imaster's Patient Record Management System contains a stored Cross-Site Scripting (XSS) vulnerability in the endpoint ‘/... |
| CVE-2025-40978 | MEDIUM | 5.1 | 0.3% | Jan 12, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a stored XSS due to a lack o... |
| CVE-2025-40977 | MEDIUM | 5.1 | 0.3% | Jan 12, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a lack of proper validation ... |
| CVE-2025-40976 | MEDIUM | 5.1 | 0.3% | Jan 12, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's TicketGo, consisting of a lack of proper validation of user ... |
| CVE-2025-40975 | MEDIUM | 5.1 | 0.3% | Jan 12, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's HRMGo, consisting of a lack of proper validation of user inp... |
| CVE-2025-14279 | HIGH | 8.1 | 0.2% | Jan 12, 2026 | MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header validat... |
| CVE-2025-14579 | MEDIUM | 4.8 | 0.2% | Jan 12, 2026 | The Quiz Maker WordPress plugin before 6.7.0.89 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2025-69276 | HIGH | 8.8 | 0.3% | Jan 12, 2026 | Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Object Injection... |
| CVE-2025-69275 | MEDIUM | 6.1 | 0.1% | Jan 12, 2026 | Dependency on Vulnerable Third-Party Component vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows DOM... |
| CVE-2025-69274 | HIGH | 8.8 | 0.2% | Jan 12, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows P... |
| CVE-2025-69273 | HIGH | 7.5 | 0.3% | Jan 12, 2026 | Improper Authentication vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Authentication Bypass.This... |
| CVE-2025-69272 | HIGH | 7.5 | 0.1% | Jan 12, 2026 | Cleartext Transmission of Sensitive Information vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sn... |
| CVE-2025-69271 | HIGH | 7.5 | 0.2% | Jan 12, 2026 | Insufficiently Protected Credentials vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Atta... |
| CVE-2025-69270 | CRITICAL | 9.8 | 0.3% | Jan 12, 2026 | Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux... |
| CVE-2025-69269 | CRITICAL | 9.8 | 0.8% | Jan 12, 2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX ... |
| CVE-2025-69268 | MEDIUM | 6.1 | 0.1% | Jan 12, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Broadcom DX... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now