2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54148 | MEDIUM | 6.5 | 0.5% | Feb 11, 2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac... |
| CVE-2025-54147 | MEDIUM | 6.5 | 0.4% | Feb 11, 2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac... |
| CVE-2025-54146 | MEDIUM | 6.5 | 0.5% | Feb 11, 2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac... |
| CVE-2025-53598 | MEDIUM | 6.5 | 0.5% | Feb 11, 2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac... |
| CVE-2025-48722 | MEDIUM | 6.5 | 0.4% | Feb 11, 2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac... |
| CVE-2025-47209 | MEDIUM | 6.5 | 0.4% | Feb 11, 2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac... |
| CVE-2025-47205 | MEDIUM | 4.9 | 0.4% | Feb 11, 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote... |
| CVE-2025-30266 | MEDIUM | 6.5 | 0.4% | Feb 11, 2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac... |
| CVE-2025-14592 | MEDIUM | 5.3 | 0.3% | Feb 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 1... |
| CVE-2025-14560 | MEDIUM | 5.4 | 0.2% | Feb 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.6, 18.7 before 18.7.4, and 1... |
| CVE-2025-12575 | MEDIUM | 5.4 | 0.2% | Feb 11, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8... |
| CVE-2025-12073 | MEDIUM | 4.3 | 0.2% | Feb 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 1... |
| CVE-2025-13650 | MEDIUM | 6.1 | 0.2% | Feb 11, 2026 | An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is not neces... |
| CVE-2025-13649 | MEDIUM | 6.1 | 0.2% | Feb 11, 2026 | An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is not nec... |
| CVE-2025-13648 | MEDIUM | 6.1 | 0.2% | Feb 11, 2026 | An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is require... |
| CVE-2025-10912 | MEDIUM | 5.4 | 0.2% | Feb 11, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Saastech Cleaning and Internet Services Inc. TemizlikY... |
| CVE-2025-15400 | MEDIUM | 6.5 | 0.3% | Feb 11, 2026 | The OpenPix for WooCommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that r... |
| CVE-2025-15524 | MEDIUM | 4.3 | 0.2% | Feb 11, 2026 | The Gallery by FooGallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ... |
| CVE-2025-13431 | MEDIUM | 6.5 | 0.2% | Feb 11, 2026 | The SlimStat Analytics plugin for WordPress is vulnerable to time-based SQL Injection via the ‘args’ parameter in all ve... |
| CVE-2025-12699 | MEDIUM | 6.7 | 0.2% | Feb 10, 2026 | The ZOLL ePCR IOS application reflects unsanitized user input into a WebView. Attacker-controlled strings placed into PC... |
| CVE-2025-54514 | MEDIUM | 4.8 | 0.1% | Feb 10, 2026 | Improper isolation of shared resources on a system on a chip by a malicious local attacker with high privileges could po... |
| CVE-2025-52536 | MEDIUM | 6.7 | 0.1% | Feb 10, 2026 | Improper Prevention of Lock Bit Modification in SEV firmware could allow a privileged attacker to downgrade firmware pot... |
| CVE-2025-52534 | MEDIUM | 5.3 | 0.3% | Feb 10, 2026 | Improper bound check within AMD CPU microcode can allow a malicious guest to write to host memory, potentially resulting... |
| CVE-2025-48517 | MEDIUM | 4.6 | 0.1% | Feb 10, 2026 | Insufficient Granularity of Access Control in SEV firmware could allow a privileged user with a malicious hypervisor to ... |
| CVE-2025-48515 | MEDIUM | 5.4 | 0.1% | Feb 10, 2026 | Insufficient parameter sanitization in AMD Secure Processor (ASP) Boot Loader could allow an attacker with access to SPI... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now