2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66560 | HIGH | 7.5 | 0.3% | Jan 7, 2026 | Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. Prior to versions 3.31.0, 3.... |
| CVE-2025-61782 | MEDIUM | 6.1 | 0.2% | Jan 7, 2026 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.... |
| CVE-2025-61492 | CRITICAL | 10 | 1.9% | Jan 7, 2026 | A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to e... |
| CVE-2025-58441 | MEDIUM | 6.5 | 0.2% | Jan 7, 2026 | Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, there is a blind server-si... |
| CVE-2025-4677 | HIGH | 7.1 | 0.2% | Jan 7, 2026 | Insufficient Session Expiration vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.Thi... |
| CVE-2025-67366 | HIGH | 7.5 | 0.5% | Jan 7, 2026 | @sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of fil... |
| CVE-2025-67364 | HIGH | 7.5 | 0.6% | Jan 7, 2026 | fast-filesystem-mcp version 3.4.0 contains a critical path traversal vulnerability in its file operation tools including... |
| CVE-2025-66837 | MEDIUM | 6.8 | 0.3% | Jan 7, 2026 | A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted... |
| CVE-2025-66786 | HIGH | 7.5 | 0.3% | Jan 7, 2026 | OpenAirInterface CN5G AMF<=v2.0.1 There is a logical error when processing JSON format requests. Unauthorized remote att... |
| CVE-2025-66686 | MEDIUM | 6.1 | 0.2% | Jan 7, 2026 | A stored Cross-Site Scripting (XSS) vulnerability exists in Perch CMS version 3.2. An authenticated attacker with admini... |
| CVE-2025-65805 | HIGH | 7.5 | 0.3% | Jan 7, 2026 | OpenAirInterface CN5G AMF<=v2.1.9 has a buffer overflow vulnerability in processing NAS messages. Unauthorized remote at... |
| CVE-2025-61489 | MEDIUM | 6.5 | 0.8% | Jan 7, 2026 | A command injection vulnerability in the shell_exec function of sonirico mcp-shell v0.3.1 allows attackers to execute ar... |
| CVE-2025-4676 | HIGH | 8.8 | 0.2% | Jan 7, 2026 | Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP C... |
| CVE-2025-4675 | HIGH | 7.1 | 0.2% | Jan 7, 2026 | Improper Check for Unusual or Exceptional Conditions vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP C... |
| CVE-2025-12543 | CRITICAL | 9.6 | 1.2% | Jan 7, 2026 | A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The... |
| CVE-2025-66838 | MEDIUM | 6.5 | 0.3% | Jan 7, 2026 | In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, a... |
| CVE-2025-62327 | MEDIUM | 4.9 | 0.2% | Jan 7, 2026 | In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credenti... |
| CVE-2025-49335 | MEDIUM | 4.9 | 0.1% | Jan 7, 2026 | Server-Side Request Forgery (SSRF) vulnerability in minnur External Media external-media allows Server Side Request Forg... |
| CVE-2025-6225 | MEDIUM | 6.9 | 0.9% | Jan 7, 2026 | Kieback&Peter Neutrino-GLT product is used for building management. It's web component "SM70 PHWEB" is vulnerable to she... |
| CVE-2025-15479 | MEDIUM | 5.4 | 0.2% | Jan 7, 2026 | Stored cross-site scripting (XSS, CWE-79) in the survey content and administration functionality in Data Illusion Zumbru... |
| CVE-2025-47552 | CRITICAL | 9.8 | 0.3% | Jan 7, 2026 | Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This is... |
| CVE-2025-46494 | HIGH | 7.1 | 0.1% | Jan 7, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesgrove Widget... |
| CVE-2025-46434 | MEDIUM | 6.5 | 0.2% | Jan 7, 2026 | Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro theplus_elementor_addon all... |
| CVE-2025-46256 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | Path Traversal: '.../...//' vulnerability in SigmaPlugin Advanced Database Cleaner PRO allows Path Traversal.This issue ... |
| CVE-2025-32303 | CRITICAL | 9.3 | 0.2% | Jan 7, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now