2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13004 | MEDIUM | 6.3 | 0.3% | Feb 12, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce P... |
| CVE-2025-13002 | MEDIUM | 6.1 | 0.2% | Feb 12, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Farktor Sof... |
| CVE-2025-15575 | MEDIUM | 5.3 | 0.1% | Feb 12, 2026 | The firmware update functionality does not verify the authenticity of the supplied firmware update files. This allows at... |
| CVE-2025-15574 | MEDIUM | 6.5 | 0.2% | Feb 12, 2026 | When connecting to the Solax Cloud MQTT server the username is the "registration number", which is the 10 character stri... |
| CVE-2025-41117 | MEDIUM | 6.1 | 0.3% | Feb 12, 2026 | Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the b... |
| CVE-2025-64074 | MEDIUM | 5.3 | 0.4% | Feb 11, 2026 | A path-traversal vulnerability in the logout functionality of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows ... |
| CVE-2025-46310 | MEDIUM | 6 | 0.2% | Feb 11, 2026 | This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14... |
| CVE-2025-46305 | MEDIUM | 5.7 | 0.3% | Feb 11, 2026 | The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i... |
| CVE-2025-46304 | MEDIUM | 5.7 | 0.3% | Feb 11, 2026 | The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i... |
| CVE-2025-46303 | MEDIUM | 5.7 | 0.3% | Feb 11, 2026 | The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i... |
| CVE-2025-46302 | MEDIUM | 5.7 | 0.3% | Feb 11, 2026 | The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i... |
| CVE-2025-46301 | MEDIUM | 5.7 | 0.3% | Feb 11, 2026 | The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i... |
| CVE-2025-46300 | MEDIUM | 5.7 | 0.3% | Feb 11, 2026 | The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i... |
| CVE-2025-43537 | MEDIUM | 5.5 | 0.5% | Feb 11, 2026 | A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 2... |
| CVE-2025-43417 | MEDIUM | 5.5 | 0.2% | Feb 11, 2026 | A path handling issue was addressed with improved logic. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.... |
| CVE-2025-43403 | MEDIUM | 5.5 | 0.2% | Feb 11, 2026 | An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS ... |
| CVE-2025-68663 | MEDIUM | 5.3 | 0.2% | Feb 11, 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a vulnerability was found in Outline's... |
| CVE-2025-70297 | MEDIUM | 6.1 | 0.2% | Feb 11, 2026 | A stored cross-site scripting (XSS) vulnerability in the recipe asset upload and media serving component in Mealie 3.3.1... |
| CVE-2025-70296 | MEDIUM | 5.4 | 0.2% | Feb 11, 2026 | A stored HTML injection vulnerability in the Recipe Notes rendering component in Mealie 3.3.1 allows remote authenticate... |
| CVE-2025-65127 | MEDIUM | 6.5 | 0.3% | Feb 11, 2026 | A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remot... |
| CVE-2025-13391 | MEDIUM | 5.8 | 0.2% | Feb 11, 2026 | The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerabl... |
| CVE-2025-12474 | MEDIUM | 4.4 | 0.1% | Feb 11, 2026 | A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This ... |
| CVE-2025-48518 | MEDIUM | 6.9 | 0.1% | Feb 11, 2026 | Improper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially result... |
| CVE-2025-48508 | MEDIUM | 6 | 0.1% | Feb 11, 2026 | Improper Hardware reset flow logic in the GPU GFX Hardware IP block could allow a privileged attacker in a guest virtual... |
| CVE-2025-68406 | MEDIUM | 6.5 | 0.5% | Feb 11, 2026 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now