2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43706 | HIGH | 7.5 | 0.3% | Jan 5, 2026 | An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 240... |
| CVE-2025-27807 | CRITICAL | 9.1 | 0.3% | Jan 5, 2026 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128... |
| CVE-2025-65922 | MEDIUM | 4.3 | 0.1% | Jan 5, 2026 | PLANKA 2.0.0 lacks X-Frame-Options and CSP frame-ancestors headers, allowing the application to be embedded within malic... |
| CVE-2025-61781 | CRITICAL | 9.1 | 0.2% | Jan 5, 2026 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.... |
| CVE-2025-59955 | MEDIUM | 5.7 | 0.3% | Jan 5, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions pri... |
| CVE-2025-59158 | HIGH | 8 | 0.5% | Jan 5, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions pri... |
| CVE-2025-59157 | HIGH | 8.8 | 1.8% | Jan 5, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0... |
| CVE-2025-59156 | HIGH | 8.8 | 0.9% | Jan 5, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0... |
| CVE-2025-55204 | CRITICAL | 9.6 | 0.6% | Jan 5, 2026 | muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Exec... |
| CVE-2025-67316 | MEDIUM | 5.4 | 0.3% | Jan 5, 2026 | An issue in realme Internet browser v.45.13.4.1 allows a remote attacker to execute arbitrary code via a crafted webpage... |
| CVE-2025-59467 | CRITICAL | 9.6 | 0.2% | Jan 5, 2026 | A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow p... |
| CVE-2025-57836 | HIGH | 7.8 | 0.1% | Jan 5, 2026 | An issue was discovered in Samsung Magician 6.3.0 through 8.3.2 on Windows. The installer creates a temporary folder wit... |
| CVE-2025-53344 | MEDIUM | 4.3 | 0.1% | Jan 5, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThimPress Thim Core allows Cross Site Request Forgery.This issue affe... |
| CVE-2025-52519 | HIGH | 7.1 | 0.1% | Jan 5, 2026 | An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, ... |
| CVE-2025-46255 | HIGH | 7.5 | 0.2% | Jan 5, 2026 | Missing Authorization vulnerability in Marketing Fire LLC LoginWP - Pro allows Accessing Functionality Not Properly Cons... |
| CVE-2025-39561 | MEDIUM | 6.5 | 0.2% | Jan 5, 2026 | Missing Authorization vulnerability in Marketing Fire, LLC LoginWP - Pro allows Accessing Functionality Not Properly Con... |
| CVE-2025-39497 | MEDIUM | 6.5 | 0.1% | Jan 5, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan Dokan Pro al... |
| CVE-2025-39484 | CRITICAL | 9.3 | 0.2% | Jan 5, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada all... |
| CVE-2025-10933 | MEDIUM | 5.3 | 0.2% | Jan 5, 2026 | An integer underflow vulnerability in the Silicon Labs Z-Wave Protocol Controller can lead to out of bounds memory reads... |
| CVE-2025-67315 | — | — | — | Jan 5, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2025-67303 | HIGH | 7.5 | 1.4% | Jan 5, 2026 | An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration a... |
| CVE-2025-65328 | MEDIUM | 6.5 | 0.2% | Jan 5, 2026 | Mega-Fence (webgate-lib.*) 25.1.914 and prior trusts the first value of the X-Forwarded-For (XFF) header as the client I... |
| CVE-2025-14346 | CRITICAL | 9.8 | 5.5% | Jan 5, 2026 | WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An... |
| CVE-2025-66376 | MEDIUM | 6.1 | 12.0% | Jan 5, 2026 | Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sh... |
| CVE-2025-15029 | CRITICAL | 9.8 | 11.2% | Jan 5, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Mon... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now