2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64119 | CRITICAL | 9.3 | 0.4% | Jan 2, 2026 | A vulnerability in Nuvation Battery Management System allows Authentication Bypass.This issue affects Battery Management... |
| CVE-2025-67268 | CRITICAL | 9.8 | 0.7% | Jan 2, 2026 | gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file... |
| CVE-2025-59389 | CRITICAL | 9.8 | 0.6% | Jan 2, 2026 | An SQL injection vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit t... |
| CVE-2025-11837 | CRITICAL | 9.8 | 1.4% | Jan 2, 2026 | An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attacker... |
| CVE-2025-65125 | CRITICAL | 9.8 | 0.3% | Jan 2, 2026 | SQL injection in gosaliajainam/online-movie-booking 5.5 in movie_details.php allows attackers to gain sensitive informat... |
| CVE-2025-15436 | CRITICAL | 9.8 | 0.4% | Jan 2, 2026 | A vulnerability has been found in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /wor... |
| CVE-2025-15435 | CRITICAL | 9.8 | 0.3% | Jan 2, 2026 | A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksh... |
| CVE-2025-15434 | CRITICAL | 9.8 | 0.3% | Jan 2, 2026 | A vulnerability was detected in Yonyou KSOA 9.0. Affected is an unknown function of the file /kp/PrintZPYG.jsp. The mani... |
| CVE-2025-15425 | CRITICAL | 9.8 | 0.5% | Jan 2, 2026 | A vulnerability was determined in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/de... |
| CVE-2025-15424 | CRITICAL | 9.8 | 0.4% | Jan 2, 2026 | A vulnerability was found in Yonyou KSOA 9.0. The affected element is an unknown function of the file /worksheet/agent_w... |
| CVE-2025-14998 | CRITICAL | 9.8 | 0.5% | Jan 2, 2026 | The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and in... |
| CVE-2025-15421 | CRITICAL | 9.8 | 0.4% | Jan 2, 2026 | A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/agent_wo... |
| CVE-2025-15420 | CRITICAL | 9.8 | 0.4% | Jan 2, 2026 | A security vulnerability has been detected in Yonyou KSOA 9.0. This affects an unknown part of the file /worksheet/agent... |
| CVE-2025-68620 | CRITICAL | 9.1 | 0.5% | Jan 1, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two featur... |
| CVE-2025-15410 | CRITICAL | 9.8 | 0.3% | Jan 1, 2026 | A vulnerability was identified in code-projects Online Guitar Store 1.0. Affected by this issue is some unknown function... |
| CVE-2025-15409 | CRITICAL | 9.8 | 0.4% | Jan 1, 2026 | A vulnerability was determined in code-projects Online Guitar Store 1.0. Affected by this vulnerability is an unknown fu... |
| CVE-2025-15408 | CRITICAL | 9.8 | 0.3% | Jan 1, 2026 | A vulnerability was found in code-projects Online Guitar Store 1.0. Affected is an unknown function of the file /admin/C... |
| CVE-2025-15407 | CRITICAL | 9.8 | 0.3% | Jan 1, 2026 | A vulnerability has been found in code-projects Online Guitar Store 1.0. This impacts an unknown function of the file /a... |
| CVE-2025-69288 | CRITICAL | 9.1 | 0.7% | Dec 31, 2025 | Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user... |
| CVE-2025-69286 | CRITICAL | 9.8 | 0.5% | Dec 31, 2025 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecu... |
| CVE-2025-34468 | CRITICAL | 9.8 | 0.6% | Dec 31, 2025 | libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a stack-based buffer overflow in address re... |
| CVE-2025-15391 | CRITICAL | 9.8 | 3.7% | Dec 31, 2025 | A weakness has been identified in D-Link DIR-806A 100CNb11. Affected is the function ssdpcgi_main of the component SSDP ... |
| CVE-2025-15114 | CRITICAL | 9.8 | 0.5% | Dec 30, 2025 | Ksenia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alar... |
| CVE-2025-15113 | CRITICAL | 9.3 | 0.4% | Dec 30, 2025 | Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that all... |
| CVE-2025-15111 | CRITICAL | 9.8 | 0.5% | Dec 30, 2025 | Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now