2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70983 | CRITICAL | 9.9 | 0.4% | Jan 23, 2026 | Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to ... |
| CVE-2025-67229 | CRITICAL | 9.8 | 0.3% | Jan 23, 2026 | An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauth... |
| CVE-2025-66719 | CRITICAL | 9.1 | 0.3% | Jan 23, 2026 | An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck... |
| CVE-2025-4320 | CRITICAL | 10 | 0.5% | Jan 23, 2026 | Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Bire... |
| CVE-2025-4319 | CRITICAL | 9.4 | 0.4% | Jan 23, 2026 | Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulne... |
| CVE-2025-15063 | CRITICAL | 9.8 | 2.1% | Jan 23, 2026 | Ollama MCP Server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote atta... |
| CVE-2025-15061 | CRITICAL | 9.8 | 2.1% | Jan 23, 2026 | Framelink Figma MCP Server fetchWithRetry Command Injection Remote Code Execution Vulnerability. This vulnerability allo... |
| CVE-2025-55705 | CRITICAL | 9.8 | 0.3% | Jan 22, 2026 | This vulnerability occurs when the system permits multiple simultaneous connections to the backend using the same charg... |
| CVE-2025-54816 | CRITICAL | 9.8 | 0.4% | Jan 22, 2026 | This vulnerability occurs when a WebSocket endpoint does not enforce proper authentication mechanisms, allowing unautho... |
| CVE-2025-56590 | CRITICAL | 9.8 | 0.5% | Jan 22, 2026 | An issue was discovered in the InsertFromURL() function of the Apryse HTML2PDF SDK thru 11.10. This vulnerability could ... |
| CVE-2025-69828 | CRITICAL | 10 | 0.5% | Jan 22, 2026 | File Upload vulnerability in TMS Global Software TMS Management Console v.6.3.7.27386.20250818 allows a remote attacker ... |
| CVE-2025-69312 | CRITICAL | 9.1 | 0.3% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows... |
| CVE-2025-69101 | CRITICAL | 9.8 | 0.5% | Jan 22, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Workreap Core workreap_core allows ... |
| CVE-2025-69079 | CRITICAL | 9.8 | 0.4% | Jan 22, 2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Sound | Musical Instruments Online Store musicplace allows O... |
| CVE-2025-69052 | CRITICAL | 9.8 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in FmeAddons Registration & Login with Mobile Phone Number for WooCommerce registrat... |
| CVE-2025-68986 | CRITICAL | 9.9 | 0.4% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Miion miion allows Upload a Web Shell to a W... |
| CVE-2025-68910 | CRITICAL | 9.9 | 0.5% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogzee blogzee allows Using Malicious File... |
| CVE-2025-68909 | CRITICAL | 9.9 | 0.5% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogistic blogistic allows Using Malicious ... |
| CVE-2025-68869 | CRITICAL | 9.8 | 0.4% | Jan 22, 2026 | Incorrect Privilege Assignment vulnerability in LazyCoders LLC LazyTasks lazytasks-project-task-management allows Privil... |
| CVE-2025-68857 | CRITICAL | 9.3 | 0.3% | Jan 22, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ichurakov Paid Dow... |
| CVE-2025-68034 | CRITICAL | 9.3 | 0.4% | Jan 22, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® Cleve... |
| CVE-2025-68018 | CRITICAL | 9.4 | 0.3% | Jan 22, 2026 | Missing Authorization vulnerability in StackWC Order Listener for WooCommerce woc-order-alert allows Exploiting Incorrec... |
| CVE-2025-68015 | CRITICAL | 9 | 0.3% | Jan 22, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner e... |
| CVE-2025-68001 | CRITICAL | 10 | 0.6% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in garidium g-FFL Checkout g-ffl-checkout allows Upload a ... |
| CVE-2025-67968 | CRITICAL | 9.9 | 0.5% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in InspiryThemes Real Homes CRM realhomes-crm allows Using... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now