2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7631 | HIGH | 8.6 | 0.3% | Feb 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tumeva Internet Te... |
| CVE-2025-12062 | HIGH | 8.8 | 0.7% | Feb 17, 2026 | The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnera... |
| CVE-2025-65716 | HIGH | 8.8 | 0.6% | Feb 16, 2026 | An issue in Visual Studio Code Extensions Markdown Preview Enhanced v0.8.18 allows attackers to execute arbitrary code v... |
| CVE-2025-65715 | HIGH | 7.8 | 0.3% | Feb 16, 2026 | An issue in the code-runner.executorMap setting of Visual Studio Code Extensions Code Runner v0.12.2 allows attackers to... |
| CVE-2025-32062 | HIGH | 8.8 | 0.4% | Feb 15, 2026 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bos... |
| CVE-2025-32061 | HIGH | 8.8 | 0.4% | Feb 15, 2026 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bos... |
| CVE-2025-32059 | HIGH | 8.8 | 0.4% | Feb 15, 2026 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bos... |
| CVE-2025-71221 | HIGH | 7 | 0.1% | Feb 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: mmp_pdma: Fix race condition in mmp_pdma... |
| CVE-2025-71220 | HIGH | 7.8 | 0.1% | Feb 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb/server: call ksmbd_session_rpc_close() on error... |
| CVE-2025-71203 | HIGH | 7 | 0.1% | Feb 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: riscv: Sanitize syscall table indexing under specul... |
| CVE-2025-71201 | HIGH | 7.1 | 0.1% | Feb 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix early read unlock of page with EOF in mi... |
| CVE-2025-70957 | HIGH | 7.5 | 0.3% | Feb 13, 2026 | A Denial of Service (DoS) vulnerability was discovered in the TON Lite Server before v2024.09. The vulnerability arises ... |
| CVE-2025-70956 | HIGH | 7.5 | 0.5% | Feb 13, 2026 | A State Pollution vulnerability was discovered in the TON Virtual Machine (TVM) before v2025.04. The issue exists in the... |
| CVE-2025-70955 | HIGH | 7.5 | 0.6% | Feb 13, 2026 | A Stack Overflow vulnerability was discovered in the TON Virtual Machine (TVM) before v2024.10. The vulnerability stems ... |
| CVE-2025-70954 | HIGH | 7.5 | 0.6% | Feb 13, 2026 | A Null Pointer Dereference vulnerability exists in the TON Virtual Machine (TVM) within the TON Blockchain before v2025.... |
| CVE-2025-70866 | HIGH | 8.8 | 0.4% | Feb 13, 2026 | LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User rol... |
| CVE-2025-15157 | HIGH | 8.8 | 0.3% | Feb 13, 2026 | The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification... |
| CVE-2025-70123 | HIGH | 7.5 | 0.3% | Feb 13, 2026 | An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a ... |
| CVE-2025-70122 | HIGH | 7.5 | 0.3% | Feb 13, 2026 | A heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of... |
| CVE-2025-70121 | HIGH | 7.5 | 0.3% | Feb 13, 2026 | An array index out of bounds vulnerability in the AMF component of free5GC v4.0.1 allows remote attackers to cause a den... |
| CVE-2025-70093 | HIGH | 7.4 | 0.3% | Feb 13, 2026 | An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response. |
| CVE-2025-14349 | HIGH | 8.8 | 0.4% | Feb 13, 2026 | Privilege Defined With Unsafe Actions, Missing Authentication for Critical Function vulnerability in Universal Software ... |
| CVE-2025-33042 | HIGH | 7.3 | 0.6% | Feb 13, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific... |
| CVE-2025-1924 | HIGH | 8.2 | 0.2% | Feb 13, 2026 | A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ... |
| CVE-2025-9293 | HIGH | 8.1 | 0.2% | Feb 13, 2026 | A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated s... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now