2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20783 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o... |
| CVE-2025-20782 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o... |
| CVE-2025-20781 | HIGH | 7.8 | 0.1% | Jan 6, 2026 | In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg... |
| CVE-2025-20780 | HIGH | 7.8 | 0.1% | Jan 6, 2026 | In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg... |
| CVE-2025-20779 | HIGH | 7 | 0.1% | Jan 6, 2026 | In display, there is a possible use after free due to a race condition. This could lead to local escalation of privilege... |
| CVE-2025-20778 | HIGH | 7.8 | 0.1% | Jan 6, 2026 | In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o... |
| CVE-2025-20762 | MEDIUM | 6.5 | 0.3% | Jan 6, 2026 | In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,... |
| CVE-2025-20761 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,... |
| CVE-2025-20760 | MEDIUM | 6.5 | 0.3% | Jan 6, 2026 | In Modem, there is a possible read of uninitialized heap data due to an uncaught exception. This could lead to remote de... |
| CVE-2025-15385 | CRITICAL | 9.8 | 0.2% | Jan 6, 2026 | Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication... |
| CVE-2025-15364 | HIGH | 7.3 | 0.2% | Jan 6, 2026 | The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up ... |
| CVE-2025-69197 | MEDIUM | 6.5 | 0.3% | Jan 6, 2026 | Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multip... |
| CVE-2025-68954 | MEDIUM | 5.4 | 0.2% | Jan 6, 2026 | Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP co... |
| CVE-2025-15444 | CRITICAL | 9.8 | 0.2% | Jan 6, 2026 | Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1... |
| CVE-2025-69230 | MEDIUM | 5.3 | 0.3% | Jan 6, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading mu... |
| CVE-2025-69229 | MEDIUM | 5.3 | 0.3% | Jan 6, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling o... |
| CVE-2025-69228 | HIGH | 7.5 | 0.3% | Jan 6, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a reques... |
| CVE-2025-69227 | HIGH | 7.5 | 0.3% | Jan 6, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an i... |
| CVE-2025-69225 | MEDIUM | 5.3 | 0.2% | Jan 6, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser... |
| CVE-2025-69226 | MEDIUM | 5.3 | 0.3% | Jan 5, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an atta... |
| CVE-2025-69224 | MEDIUM | 6.5 | 0.2% | Jan 5, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python ... |
| CVE-2025-69223 | HIGH | 7.5 | 0.5% | Jan 5, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bo... |
| CVE-2025-68953 | HIGH | 7.5 | 0.4% | Jan 5, 2026 | Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests... |
| CVE-2025-68456 | CRITICAL | 9.1 | 0.5% | Jan 5, 2026 | Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, u... |
| CVE-2025-68455 | HIGH | 7.2 | 0.8% | Jan 5, 2026 | Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 ar... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now