2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11848 | MEDIUM | 4.9 | 1.8% | Feb 24, 2026 | A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version throu... |
| CVE-2025-11847 | MEDIUM | 4.9 | 1.7% | Feb 24, 2026 | A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions thro... |
| CVE-2025-11846 | MEDIUM | 4.9 | 1.1% | Feb 24, 2026 | A null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions... |
| CVE-2025-11845 | MEDIUM | 4.9 | 0.8% | Feb 24, 2026 | A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware ve... |
| CVE-2025-69253 | MEDIUM | 5.3 | 0.3% | Feb 24, 2026 | free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of th... |
| CVE-2025-69251 | MEDIUM | 5.3 | 0.5% | Feb 24, 2026 | free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile co... |
| CVE-2025-69208 | MEDIUM | 5.3 | 0.3% | Feb 23, 2026 | free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core... |
| CVE-2025-68930 | MEDIUM | 6.5 | 0.5% | Feb 23, 2026 | Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijack... |
| CVE-2025-61147 | MEDIUM | 6.2 | 0.2% | Feb 23, 2026 | strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::comp... |
| CVE-2025-61146 | MEDIUM | 4 | 0.1% | Feb 23, 2026 | saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c. |
| CVE-2025-61145 | MEDIUM | 5 | 0.1% | Feb 23, 2026 | libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c. |
| CVE-2025-61143 | MEDIUM | 5.5 | 0.1% | Feb 23, 2026 | libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c. |
| CVE-2025-70044 | MEDIUM | 6.5 | 0.1% | Feb 23, 2026 | An issue pertaining to CWE-295: Improper Certificate Validation was discovered in fofolee uTools-quickcommand 5.0.3. |
| CVE-2025-59873 | MEDIUM | 5.9 | 0.3% | Feb 23, 2026 | An information exposure vulnerability exists in Vulnerability in HCL Software ZIE for Web. The application transmits s... |
| CVE-2025-40986 | MEDIUM | 5.1 | 0.4% | Feb 23, 2026 | Reflected Cross-Site Scripting (XSS) vulnerability in PideTuCita. This vulnerability allows an attacker to execute JavaS... |
| CVE-2025-40701 | MEDIUM | 5.1 | 0.4% | Feb 23, 2026 | Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute J... |
| CVE-2025-14339 | MEDIUM | 6.5 | 0.3% | Feb 21, 2026 | The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for Wo... |
| CVE-2025-65995 | MEDIUM | 6.5 | 0.8% | Feb 21, 2026 | When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operat... |
| CVE-2025-62326 | MEDIUM | 4.8 | 0.2% | Feb 20, 2026 | HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which wo... |
| CVE-2025-15583 | MEDIUM | 5.4 | 0.2% | Feb 20, 2026 | A weakness has been identified in detronetdip E-commerce 1.0.0. This affects the function get_safe_value of the file uti... |
| CVE-2025-69388 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Missing Authorization vulnerability in cliengo Cliengo – Chatbot cliengo allows Exploiting Incorrectly Configured Access... |
| CVE-2025-69385 | MEDIUM | 6.5 | 0.3% | Feb 20, 2026 | Missing Authorization vulnerability in AgniHD Cartify - WooCommerce Gutenberg WordPress Theme cartify allows Exploiting ... |
| CVE-2025-69325 | MEDIUM | 5.3 | 0.4% | Feb 20, 2026 | Path Traversal: '.../...//' vulnerability in primersoftware Primer MyData for Woocommerce primer-mydata allows Path Trav... |
| CVE-2025-69011 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKube Cool Tag Cl... |
| CVE-2025-68895 | MEDIUM | 6.5 | 0.4% | Feb 20, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in ahachat AhaChat Messenger Marketing ahachat-me... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now