2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70968 | CRITICAL | 9.8 | 0.5% | Jan 14, 2026 | FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE(). |
| CVE-2025-37184 | CRITICAL | 9.8 | 0.6% | Jan 14, 2026 | A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-fa... |
| CVE-2025-14502 | CRITICAL | 9.8 | 1.3% | Jan 14, 2026 | The News and Blog Designer Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and ... |
| CVE-2025-14301 | CRITICAL | 9.8 | 0.6% | Jan 14, 2026 | The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, an... |
| CVE-2025-37168 | CRITICAL | 9.1 | 0.4% | Jan 13, 2026 | Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 ope... |
| CVE-2025-68271 | CRITICAL | 10 | 0.5% | Jan 13, 2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2025-64155 | CRITICAL | 9.8 | 42.6% | Jan 13, 2026 | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet ... |
| CVE-2025-47855 | CRITICAL | 9.8 | 0.8% | Jan 13, 2026 | An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 throug... |
| CVE-2025-25249 | CRITICAL | 9.8 | 0.7% | Jan 13, 2026 | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS... |
| CVE-2025-25176 | CRITICAL | 9.1 | 0.3% | Jan 13, 2026 | Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in ... |
| CVE-2025-69992 | CRITICAL | 9.8 | 0.5% | Jan 13, 2026 | phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of a... |
| CVE-2025-69991 | CRITICAL | 9.8 | 0.4% | Jan 13, 2026 | phpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php. |
| CVE-2025-69990 | CRITICAL | 9.1 | 0.4% | Jan 13, 2026 | phpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file ... |
| CVE-2025-68811 | CRITICAL | 9.8 | 0.2% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: use rc_pageoff for memcpy byte offset svc... |
| CVE-2025-68809 | CRITICAL | 9.1 | 0.2% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: vfs: fix race on m_flags in vfs_cache ksmbd... |
| CVE-2025-68794 | CRITICAL | 9.8 | 0.2% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: iomap: adjust read range correctly for non-block-al... |
| CVE-2025-68775 | CRITICAL | 9.8 | 0.2% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/handshake: duplicate handshake cancellations le... |
| CVE-2025-65783 | CRITICAL | 9.8 | 0.5% | Jan 13, 2026 | An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.... |
| CVE-2025-12548 | CRITICAL | 9 | 1.2% | Jan 13, 2026 | A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command exe... |
| CVE-2025-11250 | CRITICAL | 9.1 | 1.4% | Jan 13, 2026 | Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper fi... |
| CVE-2025-40805 | CRITICAL | 10 | 0.6% | Jan 13, 2026 | Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthe... |
| CVE-2025-14829 | CRITICAL | 9.1 | 0.3% | Jan 13, 2026 | The E-xact | Hosted Payment | WordPress plugin through 2.0 is vulnerable to arbitrary file deletion due to insufficient ... |
| CVE-2025-10915 | CRITICAL | 9.8 | 0.3% | Jan 13, 2026 | The Dreamer Blog WordPress theme through 1.2 is vulnerable to arbitrary installations due to a missing capability check... |
| CVE-2025-67146 | CRITICAL | 9.4 | 0.6% | Jan 12, 2026 | Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1)... |
| CVE-2025-29329 | CRITICAL | 9.8 | 1.0% | Jan 12, 2026 | Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now