2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61492 | CRITICAL | 10 | 1.9% | Jan 7, 2026 | A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to e... |
| CVE-2025-12543 | CRITICAL | 9.6 | 1.4% | Jan 7, 2026 | A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The... |
| CVE-2025-47552 | CRITICAL | 9.8 | 0.3% | Jan 7, 2026 | Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This is... |
| CVE-2025-32303 | CRITICAL | 9.3 | 0.2% | Jan 7, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH ... |
| CVE-2025-68637 | CRITICAL | 9.1 | 0.2% | Jan 7, 2026 | The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This... |
| CVE-2025-15018 | CRITICAL | 9.8 | 0.3% | Jan 7, 2026 | The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to... |
| CVE-2025-15471 | CRITICAL | 9.8 | 12.1% | Jan 7, 2026 | A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goform... |
| CVE-2025-30996 | CRITICAL | 9.9 | 0.4% | Jan 6, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themi... |
| CVE-2025-14942 | CRITICAL | 9.8 | 0.4% | Jan 6, 2026 | wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to ... |
| CVE-2025-60534 | CRITICAL | 9.8 | 0.7% | Jan 6, 2026 | Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectiv... |
| CVE-2025-39477 | CRITICAL | 9.8 | 0.3% | Jan 6, 2026 | Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2025-65212 | CRITICAL | 9.8 | 4.6% | Jan 6, 2026 | An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the dev... |
| CVE-2025-60262 | CRITICAL | 9.8 | 0.5% | Jan 6, 2026 | An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a mi... |
| CVE-2025-15001 | CRITICAL | 9.8 | 0.3% | Jan 6, 2026 | The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all vers... |
| CVE-2025-14996 | CRITICAL | 9.8 | 0.3% | Jan 6, 2026 | The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via accoun... |
| CVE-2025-15385 | CRITICAL | 9.8 | 0.2% | Jan 6, 2026 | Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication... |
| CVE-2025-15444 | CRITICAL | 9.8 | 0.2% | Jan 6, 2026 | Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1... |
| CVE-2025-68456 | CRITICAL | 9.1 | 0.5% | Jan 5, 2026 | Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, u... |
| CVE-2025-65110 | CRITICAL | 9.3 | 0.5% | Jan 5, 2026 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design... |
| CVE-2025-67397 | CRITICAL | 9.1 | 0.7% | Jan 5, 2026 | An issue in Passy v.1.6.3 allows a remote authenticated attacker to execute arbitrary commands via a crafted HTTP reques... |
| CVE-2025-27807 | CRITICAL | 9.1 | 0.3% | Jan 5, 2026 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128... |
| CVE-2025-61781 | CRITICAL | 9.1 | 0.2% | Jan 5, 2026 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.... |
| CVE-2025-55204 | CRITICAL | 9.6 | 0.6% | Jan 5, 2026 | muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Exec... |
| CVE-2025-59467 | CRITICAL | 9.6 | 0.2% | Jan 5, 2026 | A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow p... |
| CVE-2025-39484 | CRITICAL | 9.3 | 0.2% | Jan 5, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada all... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now