2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9292 | HIGH | 7.5 | 0.3% | Feb 13, 2026 | A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed u... |
| CVE-2025-40905 | HIGH | 7.3 | 0.3% | Feb 13, 2026 | WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptograp... |
| CVE-2025-67433 | HIGH | 7.5 | 0.4% | Feb 12, 2026 | A heap buffer overflow in the processRequest function of Open TFTP Server MultiThreaded v1.7 allows attackers to cause a... |
| CVE-2025-67432 | HIGH | 7.5 | 0.3% | Feb 12, 2026 | A stack overflow in the ZBarcode_Encode function of Monkeybread Software MBS DynaPDF Plugin v21.3.1.1 allows attackers t... |
| CVE-2025-69807 | HIGH | 7.5 | 0.4% | Feb 12, 2026 | p2r3 Bareiron commit: 8e4d4020d is vulnerable to Buffer Overflow, which allows unauthenticated remote attackers to cause... |
| CVE-2025-69806 | HIGH | 7.5 | 0.3% | Feb 12, 2026 | p2r3 bareiron commit: 8e4d4020d contains an Out-of-bounds Read, which allows unauthenticated remote attackers to get rel... |
| CVE-2025-63421 | HIGH | 7.8 | 0.1% | Feb 12, 2026 | An issue in filosoft Comerc.32 Commercial Invoicing v.16.0.0.3 allows a local attacker to execute arbitrary code via the... |
| CVE-2025-54519 | HIGH | 7.3 | 0.1% | Feb 12, 2026 | A DLL hijacking vulnerability in Doc Nav could allow a local attacker to achieve privilege escalation, potentially resul... |
| CVE-2025-52533 | HIGH | 8.7 | 0.3% | Feb 12, 2026 | Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and ... |
| CVE-2025-61880 | HIGH | 8.8 | 0.6% | Feb 12, 2026 | In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution. |
| CVE-2025-61879 | HIGH | 7.7 | 0.3% | Feb 12, 2026 | In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mech... |
| CVE-2025-55210 | HIGH | 7.5 | 0.3% | Feb 12, 2026 | FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to 17.0.5 and 16.0.17, F... |
| CVE-2025-54756 | HIGH | 8.6 | 0.1% | Feb 12, 2026 | BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 use a default passwo... |
| CVE-2025-70886 | HIGH | 7.5 | 0.4% | Feb 12, 2026 | An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the ... |
| CVE-2025-15577 | HIGH | 7.5 | 0.5% | Feb 12, 2026 | An unauthenticated attacker can exploit this vulnerability by manipulating URL to achieve arbitrary file read access.Thi... |
| CVE-2025-46290 | HIGH | 7.5 | 0.9% | Feb 11, 2026 | A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPad... |
| CVE-2025-64487 | HIGH | 7.6 | 0.2% | Feb 11, 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability e... |
| CVE-2025-69871 | HIGH | 8.1 | 0.4% | Feb 11, 2026 | A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and earlier in the registerUsage() function of the prom... |
| CVE-2025-70084 | HIGH | 7.5 | 0.8% | Feb 11, 2026 | Directory traversal vulnerability in OpenSatKit 2.2.1 allows attackers to gain access to sensitive information or delete... |
| CVE-2025-70083 | HIGH | 7.8 | 0.2% | Feb 11, 2026 | An issue was discovered in OpenSatKit 2.2.1. The DirName field in the telecommand is provided by the ground segment and ... |
| CVE-2025-70029 | HIGH | 7.5 | 0.3% | Feb 11, 2026 | An issue in Sunbird-Ed SunbirdEd-portal v1.13.4 allows attackers to obtain sensitive information. The application disabl... |
| CVE-2025-65480 | HIGH | 8.8 | 0.7% | Feb 11, 2026 | An issue was discovered in Pacom Unison Client 5.13.1. Authenticated users can inject malicious scripts in the Report Te... |
| CVE-2025-65128 | HIGH | 8.1 | 0.3% | Feb 11, 2026 | A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.... |
| CVE-2025-61969 | HIGH | 7 | 0.1% | Feb 11, 2026 | Incorrect permission assignment in AMD µProf may allow a local user-privileged attacker to achieve privilege escalation,... |
| CVE-2025-52541 | HIGH | 7.3 | 0.1% | Feb 11, 2026 | A DLL hijacking vulnerability in Vivado could allow a local attacker to achieve privilege escalation, potentially result... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now