2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64691 | CRITICAL | 9.3 | 0.3% | Jan 16, 2026 | The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scr... |
| CVE-2025-61937 | CRITICAL | 10 | 1.5% | Jan 16, 2026 | The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS sys... |
| CVE-2025-14237 | CRITICAL | 9.8 | 0.9% | Jan 16, 2026 | Buffer overflow in XPS font parse processing on Small Office Multifunction Printers and Laser Printers(*) which may allo... |
| CVE-2025-14236 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Buffer overflow in Address Book attribute tag processing on Small Office Multifunction Printers(*) which may allow an at... |
| CVE-2025-14235 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Buffer overflow in XPS font fpgm data processing on Small Office Multifunction Printers and Laser Printers(*) which may ... |
| CVE-2025-14234 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Buffer overflow in CPCA list processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an ... |
| CVE-2025-14233 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may all... |
| CVE-2025-14232 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Buffer overflow in XML processing of XPS file in Small Office Multifunction Printers and Laser Printers(*) which may all... |
| CVE-2025-14231 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Buffer overflow in print job processing by WSD on Small Office Multifunction Printers and Laser Printers(*) which may al... |
| CVE-2025-67822 | CRITICAL | 9.4 | 0.4% | Jan 15, 2026 | A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.... |
| CVE-2025-70892 | CRITICAL | 9.8 | 0.4% | Jan 15, 2026 | Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The a... |
| CVE-2025-67647 | CRITICAL | 9.1 | 0.5% | Jan 15, 2026 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, Svelt... |
| CVE-2025-66417 | CRITICAL | 9.8 | 0.4% | Jan 15, 2026 | GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQ... |
| CVE-2025-62193 | CRITICAL | 9.8 | 1.2% | Jan 15, 2026 | Sites running NOAA PMEL Live Access Server (LAS) are vulnerable to remote code execution via specially crafted requests ... |
| CVE-2025-67079 | CRITICAL | 9.8 | 0.4% | Jan 15, 2026 | File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL eng... |
| CVE-2025-67084 | CRITICAL | 9.9 | 0.4% | Jan 15, 2026 | File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files int... |
| CVE-2025-70968 | CRITICAL | 9.8 | 0.5% | Jan 14, 2026 | FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE(). |
| CVE-2025-37184 | CRITICAL | 9.8 | 0.6% | Jan 14, 2026 | A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-fa... |
| CVE-2025-14502 | CRITICAL | 9.8 | 1.3% | Jan 14, 2026 | The News and Blog Designer Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and ... |
| CVE-2025-14301 | CRITICAL | 9.8 | 0.6% | Jan 14, 2026 | The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, an... |
| CVE-2025-37168 | CRITICAL | 9.1 | 0.4% | Jan 13, 2026 | Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 ope... |
| CVE-2025-68271 | CRITICAL | 10 | 0.5% | Jan 13, 2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2025-64155 | CRITICAL | 9.8 | 42.6% | Jan 13, 2026 | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet ... |
| CVE-2025-47855 | CRITICAL | 9.8 | 0.8% | Jan 13, 2026 | An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 throug... |
| CVE-2025-25249 | CRITICAL | 9.8 | 0.8% | Jan 13, 2026 | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now