2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-25176 | CRITICAL | 9.1 | 0.3% | Jan 13, 2026 | Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in ... |
| CVE-2025-69992 | CRITICAL | 9.8 | 0.5% | Jan 13, 2026 | phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of a... |
| CVE-2025-69991 | CRITICAL | 9.8 | 0.4% | Jan 13, 2026 | phpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php. |
| CVE-2025-69990 | CRITICAL | 9.1 | 0.4% | Jan 13, 2026 | phpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file ... |
| CVE-2025-68811 | CRITICAL | 9.8 | 0.2% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: use rc_pageoff for memcpy byte offset svc... |
| CVE-2025-68809 | CRITICAL | 9.1 | 0.2% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: vfs: fix race on m_flags in vfs_cache ksmbd... |
| CVE-2025-68794 | CRITICAL | 9.8 | 0.5% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: iomap: adjust read range correctly for non-block-al... |
| CVE-2025-68775 | CRITICAL | 9.8 | 0.2% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/handshake: duplicate handshake cancellations le... |
| CVE-2025-65783 | CRITICAL | 9.8 | 0.5% | Jan 13, 2026 | An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.... |
| CVE-2025-12548 | CRITICAL | 9 | 1.3% | Jan 13, 2026 | A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command exe... |
| CVE-2025-11250 | CRITICAL | 9.1 | 1.4% | Jan 13, 2026 | Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper fi... |
| CVE-2025-40805 | CRITICAL | 10 | 0.6% | Jan 13, 2026 | Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthe... |
| CVE-2025-14829 | CRITICAL | 9.1 | 0.3% | Jan 13, 2026 | The E-xact | Hosted Payment | WordPress plugin through 2.0 is vulnerable to arbitrary file deletion due to insufficient ... |
| CVE-2025-10915 | CRITICAL | 9.8 | 0.3% | Jan 13, 2026 | The Dreamer Blog WordPress theme through 1.2 is vulnerable to arbitrary installations due to a missing capability check... |
| CVE-2025-67146 | CRITICAL | 9.4 | 0.6% | Jan 12, 2026 | Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1)... |
| CVE-2025-29329 | CRITICAL | 9.8 | 1.0% | Jan 12, 2026 | Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote ... |
| CVE-2025-12420 | CRITICAL | 9.8 | 45.5% | Jan 12, 2026 | A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersona... |
| CVE-2025-67147 | CRITICAL | 9.8 | 0.3% | Jan 12, 2026 | Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', a... |
| CVE-2025-66802 | CRITICAL | 9.8 | 0.8% | Jan 12, 2026 | Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receive... |
| CVE-2025-51567 | CRITICAL | 9.1 | 0.4% | Jan 12, 2026 | A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote a... |
| CVE-2025-68472 | CRITICAL | 9.1 | 19.2% | Jan 12, 2026 | MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenti... |
| CVE-2025-63314 | CRITICAL | 10 | 0.3% | Jan 12, 2026 | A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to a... |
| CVE-2025-46070 | CRITICAL | 9.8 | 0.4% | Jan 12, 2026 | An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe compon... |
| CVE-2025-46066 | CRITICAL | 9.9 | 0.3% | Jan 12, 2026 | An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges |
| CVE-2025-65552 | CRITICAL | 9.8 | 0.4% | Jan 12, 2026 | D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication chan... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now