2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64123 | CRITICAL | 9.8 | 0.3% | Jan 2, 2026 | Unintended Proxy or Intermediary vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Network Boundary B... |
| CVE-2025-64122 | MEDIUM | 5.5 | 0.1% | Jan 2, 2026 | Insufficiently Protected Credentials vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Signature Spoo... |
| CVE-2025-64121 | CRITICAL | 9.8 | 0.4% | Jan 2, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Nuvation Energy Multi-Stack Controller (MSC) a... |
| CVE-2025-64120 | HIGH | 8.8 | 0.9% | Jan 2, 2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Ene... |
| CVE-2025-64119 | CRITICAL | 9.3 | 0.4% | Jan 2, 2026 | A vulnerability in Nuvation Battery Management System allows Authentication Bypass.This issue affects Battery Management... |
| CVE-2025-69417 | MEDIUM | 4.3 | 0.3% | Jan 2, 2026 | In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share toke... |
| CVE-2025-69416 | MEDIUM | 4.3 | 0.3% | Jan 2, 2026 | In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other toke... |
| CVE-2025-69415 | HIGH | 7.1 | 0.3% | Jan 2, 2026 | In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly a... |
| CVE-2025-69414 | HIGH | 7.1 | 0.2% | Jan 2, 2026 | Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call wit... |
| CVE-2025-67160 | HIGH | 7.5 | 0.9% | Jan 2, 2026 | An issue in Vatilon v1.12.37-20240124 allows attackers to access sensitive directories and files via a directory travers... |
| CVE-2025-67159 | HIGH | 7.5 | 0.3% | Jan 2, 2026 | Vatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext. |
| CVE-2025-67158 | HIGH | 7.5 | 0.5% | Jan 2, 2026 | An authentication bypass in the /cgi-bin/jvsweb.cgi endpoint of Revotech I6032W-FHW v1.0.0014 - 20210517 allows attacker... |
| CVE-2025-35002 | — | — | — | Jan 2, 2026 | Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. |
| CVE-2025-35001 | — | — | — | Jan 2, 2026 | Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. |
| CVE-2025-35000 | — | — | — | Jan 2, 2026 | Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. |
| CVE-2025-34999 | — | — | — | Jan 2, 2026 | Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. |
| CVE-2025-34998 | — | — | — | Jan 2, 2026 | Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. |
| CVE-2025-34997 | — | — | — | Jan 2, 2026 | Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. |
| CVE-2025-34996 | — | — | — | Jan 2, 2026 | Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. |
| CVE-2025-34995 | — | — | — | Jan 2, 2026 | Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. |
| CVE-2025-34994 | — | — | — | Jan 2, 2026 | Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. |
| CVE-2025-34993 | — | — | — | Jan 2, 2026 | Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. |
| CVE-2025-34992 | — | — | — | Jan 2, 2026 | Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. |
| CVE-2025-34991 | — | — | — | Jan 2, 2026 | Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. |
| CVE-2025-34990 | — | — | — | Jan 2, 2026 | Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now