2025 CVE Vulnerabilities
45,152 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53591 | MEDIUM | 6.5 | 0.3% | Jan 2, 2026 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2025-53590 | MEDIUM | 4.9 | 0.3% | Jan 2, 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote... |
| CVE-2025-53589 | MEDIUM | 4.9 | 0.3% | Jan 2, 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote... |
| CVE-2025-53414 | MEDIUM | 4.9 | 0.3% | Jan 2, 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote... |
| CVE-2025-53405 | MEDIUM | 4.9 | 0.3% | Jan 2, 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote... |
| CVE-2025-52872 | HIGH | 8.1 | 0.3% | Jan 2, 2026 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker... |
| CVE-2025-52864 | HIGH | 8.1 | 0.3% | Jan 2, 2026 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker... |
| CVE-2025-52863 | HIGH | 8.1 | 0.3% | Jan 2, 2026 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker... |
| CVE-2025-52431 | MEDIUM | 4.9 | 0.3% | Jan 2, 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote... |
| CVE-2025-52430 | MEDIUM | 4.9 | 0.3% | Jan 2, 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote... |
| CVE-2025-52426 | MEDIUM | 4.9 | 0.3% | Jan 2, 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote... |
| CVE-2025-47208 | MEDIUM | 6.5 | 0.3% | Jan 2, 2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating... |
| CVE-2025-45286 | MEDIUM | 6.1 | 0.2% | Jan 2, 2026 | A cross-site scripting (XSS) vulnerability in mccutchen httpbin v2.17.1 allows attackers to execute arbitrary web script... |
| CVE-2025-44013 | MEDIUM | 6.5 | 0.3% | Jan 2, 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote... |
| CVE-2025-15438 | HIGH | 7.2 | 0.4% | Jan 2, 2026 | A vulnerability was determined in PluXml up to 5.8.22. Affected is the function FileCookieJar::__destruct of the file co... |
| CVE-2025-15437 | MEDIUM | 5.4 | 0.2% | Jan 2, 2026 | A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variabl... |
| CVE-2025-15436 | CRITICAL | 9.8 | 0.4% | Jan 2, 2026 | A vulnerability has been found in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /wor... |
| CVE-2025-15435 | CRITICAL | 9.8 | 0.3% | Jan 2, 2026 | A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksh... |
| CVE-2025-15434 | CRITICAL | 9.8 | 0.3% | Jan 2, 2026 | A vulnerability was detected in Yonyou KSOA 9.0. Affected is an unknown function of the file /kp/PrintZPYG.jsp. The mani... |
| CVE-2025-15432 | HIGH | 7.5 | 0.6% | Jan 2, 2026 | A vulnerability has been found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. This vulnerability af... |
| CVE-2025-15431 | HIGH | 8.8 | 0.7% | Jan 2, 2026 | A flaw has been found in UTT 进取 512W 1.7.7-171114. This affects the function strcpy of the file /goform/formFtpServerDir... |
| CVE-2025-15430 | HIGH | 8.8 | 0.7% | Jan 2, 2026 | A vulnerability was detected in UTT 进取 512W 1.7.7-171114. Affected by this issue is the function strcpy of the file /gof... |
| CVE-2025-15429 | HIGH | 8.8 | 0.8% | Jan 2, 2026 | A security vulnerability has been detected in UTT 进取 512W 1.7.7-171114. Affected by this vulnerability is the function s... |
| CVE-2025-14072 | MEDIUM | 5.3 | 0.3% | Jan 2, 2026 | The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the... |
| CVE-2025-13456 | MEDIUM | 6.1 | 0.2% | Jan 2, 2026 | The ShopBuilder WordPress plugin before 3.2.2 does not sanitise and escape a parameter before outputting it back in the... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now