2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14358 | HIGH | 7.5 | 0.3% | Jan 8, 2026 | Missing Authorization vulnerability in sizam REHub Framework rehub-framework allows Accessing Functionality Not Properly... |
| CVE-2025-14017 | MEDIUM | 6.3 | 0.1% | Jan 8, 2026 | When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadver... |
| CVE-2025-13504 | HIGH | 7.1 | 0.2% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Real Est... |
| CVE-2025-13034 | MEDIUM | 5.9 | 0.2% | Jan 8, 2026 | When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey` with the curl tool,curl should check the pu... |
| CVE-2025-12551 | HIGH | 7.1 | 0.2% | Jan 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins ListingH... |
| CVE-2025-12550 | HIGH | 8.1 | 0.5% | Jan 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-12549 | HIGH | 8.1 | 0.5% | Jan 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-13679 | MEDIUM | 6.5 | 0.2% | Jan 8, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of data d... |
| CVE-2025-14275 | MEDIUM | 6.4 | 0.2% | Jan 8, 2026 | The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu... |
| CVE-2025-12640 | MEDIUM | 4.3 | 0.2% | Jan 8, 2026 | The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vul... |
| CVE-2025-15346 | CRITICAL | 9.3 | 0.3% | Jan 8, 2026 | A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client ... |
| CVE-2025-69262 | HIGH | 7.8 | 0.9% | Jan 7, 2026 | pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment... |
| CVE-2025-62224 | LOW | 3.5 | 0.3% | Jan 7, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacke... |
| CVE-2025-69264 | CRITICAL | 9.8 | 1.0% | Jan 7, 2026 | pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during ... |
| CVE-2025-69263 | HIGH | 8.8 | 0.3% | Jan 7, 2026 | pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the l... |
| CVE-2025-69222 | HIGH | 8.1 | 4.1% | Jan 7, 2026 | LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side request forgery (SSRF... |
| CVE-2025-13151 | HIGH | 7.5 | 1.1% | Jan 7, 2026 | Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resultin... |
| CVE-2025-12776 | MEDIUM | 5.4 | 0.1% | Jan 7, 2026 | The Report Builder component of the application stores user input directly in a web page and displays it to other users,... |
| CVE-2025-69255 | MEDIUM | 4 | 0.3% | Jan 7, 2026 | RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.77, a malformed g... |
| CVE-2025-69221 | MEDIUM | 4.3 | 0.2% | Jan 7, 2026 | LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control when que... |
| CVE-2025-69220 | MEDIUM | 5.9 | 0.3% | Jan 7, 2026 | LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file... |
| CVE-2025-68705 | CRITICAL | 9.8 | 6.6% | Jan 7, 2026 | RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.78, RustFS contai... |
| CVE-2025-66620 | HIGH | 7.2 | 0.4% | Jan 7, 2026 | An unused webshell in MicroServer allows unlimited login attempts, with sudo rights on certain files and directories. An... |
| CVE-2025-64305 | HIGH | 7.1 | 0.1% | Jan 7, 2026 | MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vend... |
| CVE-2025-61939 | MEDIUM | 4.4 | 0.2% | Jan 7, 2026 | An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authe... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now