2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67945 | CRITICAL | 9.3 | 0.4% | Jan 22, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MailerLite MailerL... |
| CVE-2025-67944 | CRITICAL | 9.1 | 0.5% | Jan 22, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-test... |
| CVE-2025-67617 | CRITICAL | 9.8 | 0.5% | Jan 22, 2026 | Deserialization of Untrusted Data vulnerability in themeton Consult Aid consultaid allows Object Injection.This issue af... |
| CVE-2025-62056 | CRITICAL | 9.9 | 0.5% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes News Event news-event.This issue affects Ne... |
| CVE-2025-62050 | CRITICAL | 9.9 | 0.5% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogmatic blogmatic.This issue affects Blog... |
| CVE-2025-50002 | CRITICAL | 10 | 0.5% | Jan 22, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Farost Energia energia allows Upload a Web Shell to a W... |
| CVE-2025-49055 | CRITICAL | 9.3 | 0.4% | Jan 22, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Le... |
| CVE-2025-69764 | CRITICAL | 9.8 | 1.0% | Jan 22, 2026 | Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handl... |
| CVE-2025-64097 | CRITICAL | 9.8 | 0.4% | Jan 22, 2026 | NervesHub is a web service that allows users to manage over-the-air (OTA) firmware updates of devices in the field. A vu... |
| CVE-2025-27378 | CRITICAL | 9.8 | 0.4% | Jan 22, 2026 | AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic f... |
| CVE-2025-69766 | CRITICAL | 9.8 | 0.7% | Jan 21, 2026 | Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handl... |
| CVE-2025-69763 | CRITICAL | 9.8 | 0.8% | Jan 21, 2026 | Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memor... |
| CVE-2025-69762 | CRITICAL | 9.8 | 0.8% | Jan 21, 2026 | Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the list parameter, which can cause memory ... |
| CVE-2025-15521 | CRITICAL | 9.8 | 0.4% | Jan 21, 2026 | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege e... |
| CVE-2025-55130 | CRITICAL | 9.1 | 1.6% | Jan 20, 2026 | A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions u... |
| CVE-2025-56005 | CRITICAL | 9.8 | 16.9% | Jan 20, 2026 | An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the ... |
| CVE-2025-55423 | CRITICAL | 9.8 | 3.3% | Jan 20, 2026 | A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the contr... |
| CVE-2025-65482 | CRITICAL | 9.8 | 0.5% | Jan 20, 2026 | An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitra... |
| CVE-2025-64087 | CRITICAL | 9.8 | 0.5% | Jan 20, 2026 | A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.... |
| CVE-2025-36418 | CRITICAL | 9.8 | 0.1% | Jan 20, 2026 | IBM ApplinX 11.1 is vulnerable due to a privilege escalation vulnerability due to improper verification of JWT tokens. A... |
| CVE-2025-14533 | CRITICAL | 9.8 | 1.0% | Jan 20, 2026 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, a... |
| CVE-2025-55252 | CRITICAL | 9.8 | 0.1% | Jan 19, 2026 | HCL AION version 2 is affected by a Weak Password Policy vulnerability. This can allow the use of easily guessable pas... |
| CVE-2025-55251 | CRITICAL | 9.8 | 0.2% | Jan 19, 2026 | HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re... |
| CVE-2025-52660 | CRITICAL | 9.8 | 0.3% | Jan 19, 2026 | HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re... |
| CVE-2025-11043 | CRITICAL | 9.1 | 0.2% | Jan 19, 2026 | An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL over TLS client used in Automation Studio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now