2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14346 | CRITICAL | 9.8 | 5.5% | Jan 5, 2026 | WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An... |
| CVE-2025-15029 | CRITICAL | 9.8 | 11.2% | Jan 5, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Mon... |
| CVE-2025-15026 | CRITICAL | 9.8 | 0.4% | Jan 5, 2026 | Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import modul... |
| CVE-2025-68865 | CRITICAL | 9.3 | 0.2% | Jan 5, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility ... |
| CVE-2025-31048 | CRITICAL | 9.9 | 0.3% | Jan 5, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Themify Shopo allows Upload a Web Shell to a Web Server... |
| CVE-2025-30633 | CRITICAL | 9.3 | 0.2% | Jan 5, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Nat... |
| CVE-2025-15458 | CRITICAL | 9.8 | 0.5% | Jan 5, 2026 | A vulnerability was determined in bg5sbk MiniCMS up to 1.8. This affects an unknown function of the file /mc-admin/post-... |
| CVE-2025-15457 | CRITICAL | 9.8 | 0.5% | Jan 5, 2026 | A vulnerability was found in bg5sbk MiniCMS up to 1.8. The impacted element is an unknown function of the file /minicms/... |
| CVE-2025-15449 | CRITICAL | 9.1 | 0.6% | Jan 5, 2026 | A vulnerability was determined in cld378632668 JavaMall up to 994f1e2b019378ec9444cdf3fce2d5b5f72d28f0. Affected is the ... |
| CVE-2025-15448 | CRITICAL | 9.8 | 0.3% | Jan 5, 2026 | A vulnerability was found in cld378632668 JavaMall up to 994f1e2b019378ec9444cdf3fce2d5b5f72d28f0. This impacts the func... |
| CVE-2025-3654 | CRITICAL | 9.8 | 0.2% | Jan 4, 2026 | Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows un... |
| CVE-2025-3653 | CRITICAL | 9.8 | 0.2% | Jan 4, 2026 | Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an improper access control vulnerability that allows u... |
| CVE-2025-15115 | CRITICAL | 9.8 | 0.3% | Jan 4, 2026 | Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authentication bypass vulnerability that allows una... |
| CVE-2025-64125 | CRITICAL | 9.4 | 0.2% | Jan 3, 2026 | A vulnerability in Nuvation Energy nCloud VPN Service allowed Network Boundary Bridging.This issue affected the nCloud V... |
| CVE-2025-64123 | CRITICAL | 9.8 | 0.3% | Jan 2, 2026 | Unintended Proxy or Intermediary vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Network Boundary B... |
| CVE-2025-64121 | CRITICAL | 9.8 | 0.4% | Jan 2, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Nuvation Energy Multi-Stack Controller (MSC) a... |
| CVE-2025-64119 | CRITICAL | 9.3 | 0.4% | Jan 2, 2026 | A vulnerability in Nuvation Battery Management System allows Authentication Bypass.This issue affects Battery Management... |
| CVE-2025-67268 | CRITICAL | 9.8 | 0.7% | Jan 2, 2026 | gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file... |
| CVE-2025-59389 | CRITICAL | 9.8 | 0.6% | Jan 2, 2026 | An SQL injection vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit t... |
| CVE-2025-11837 | CRITICAL | 9.8 | 1.4% | Jan 2, 2026 | An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attacker... |
| CVE-2025-65125 | CRITICAL | 9.8 | 0.3% | Jan 2, 2026 | SQL injection in gosaliajainam/online-movie-booking 5.5 in movie_details.php allows attackers to gain sensitive informat... |
| CVE-2025-15436 | CRITICAL | 9.8 | 0.4% | Jan 2, 2026 | A vulnerability has been found in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /wor... |
| CVE-2025-15435 | CRITICAL | 9.8 | 0.3% | Jan 2, 2026 | A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksh... |
| CVE-2025-15434 | CRITICAL | 9.8 | 0.3% | Jan 2, 2026 | A vulnerability was detected in Yonyou KSOA 9.0. Affected is an unknown function of the file /kp/PrintZPYG.jsp. The mani... |
| CVE-2025-15425 | CRITICAL | 9.8 | 0.5% | Jan 2, 2026 | A vulnerability was determined in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/de... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now