2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15444 | CRITICAL | 9.8 | 0.2% | Jan 6, 2026 | Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1... |
| CVE-2025-68456 | CRITICAL | 9.1 | 0.5% | Jan 5, 2026 | Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, u... |
| CVE-2025-65110 | CRITICAL | 9.3 | 0.5% | Jan 5, 2026 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design... |
| CVE-2025-67397 | CRITICAL | 9.1 | 0.7% | Jan 5, 2026 | An issue in Passy v.1.6.3 allows a remote authenticated attacker to execute arbitrary commands via a crafted HTTP reques... |
| CVE-2025-27807 | CRITICAL | 9.1 | 0.3% | Jan 5, 2026 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128... |
| CVE-2025-61781 | CRITICAL | 9.1 | 0.2% | Jan 5, 2026 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.... |
| CVE-2025-55204 | CRITICAL | 9.6 | 0.6% | Jan 5, 2026 | muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Exec... |
| CVE-2025-59467 | CRITICAL | 9.6 | 0.2% | Jan 5, 2026 | A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow p... |
| CVE-2025-39484 | CRITICAL | 9.3 | 0.2% | Jan 5, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada all... |
| CVE-2025-14346 | CRITICAL | 9.8 | 5.5% | Jan 5, 2026 | WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An... |
| CVE-2025-15029 | CRITICAL | 9.8 | 11.2% | Jan 5, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Mon... |
| CVE-2025-15026 | CRITICAL | 9.8 | 0.4% | Jan 5, 2026 | Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import modul... |
| CVE-2025-68865 | CRITICAL | 9.3 | 0.2% | Jan 5, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility ... |
| CVE-2025-31048 | CRITICAL | 9.9 | 0.3% | Jan 5, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Themify Shopo allows Upload a Web Shell to a Web Server... |
| CVE-2025-30633 | CRITICAL | 9.3 | 0.2% | Jan 5, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Nat... |
| CVE-2025-15458 | CRITICAL | 9.8 | 0.5% | Jan 5, 2026 | A vulnerability was determined in bg5sbk MiniCMS up to 1.8. This affects an unknown function of the file /mc-admin/post-... |
| CVE-2025-15457 | CRITICAL | 9.8 | 0.5% | Jan 5, 2026 | A vulnerability was found in bg5sbk MiniCMS up to 1.8. The impacted element is an unknown function of the file /minicms/... |
| CVE-2025-15449 | CRITICAL | 9.1 | 0.6% | Jan 5, 2026 | A vulnerability was determined in cld378632668 JavaMall up to 994f1e2b019378ec9444cdf3fce2d5b5f72d28f0. Affected is the ... |
| CVE-2025-15448 | CRITICAL | 9.8 | 0.3% | Jan 5, 2026 | A vulnerability was found in cld378632668 JavaMall up to 994f1e2b019378ec9444cdf3fce2d5b5f72d28f0. This impacts the func... |
| CVE-2025-3654 | CRITICAL | 9.8 | 0.2% | Jan 4, 2026 | Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows un... |
| CVE-2025-3653 | CRITICAL | 9.8 | 0.2% | Jan 4, 2026 | Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an improper access control vulnerability that allows u... |
| CVE-2025-15115 | CRITICAL | 9.8 | 0.3% | Jan 4, 2026 | Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authentication bypass vulnerability that allows una... |
| CVE-2025-64125 | CRITICAL | 9.4 | 0.2% | Jan 3, 2026 | A vulnerability in Nuvation Energy nCloud VPN Service allowed Network Boundary Bridging.This issue affected the nCloud V... |
| CVE-2025-64123 | CRITICAL | 9.8 | 0.3% | Jan 2, 2026 | Unintended Proxy or Intermediary vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Network Boundary B... |
| CVE-2025-64121 | CRITICAL | 9.8 | 0.4% | Jan 2, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Nuvation Energy Multi-Stack Controller (MSC) a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now