2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66597 | HIGH | 7.5 | 0.2% | Feb 9, 2026 | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product supports weak cr... |
| CVE-2025-66608 | HIGH | 7.5 | 0.4% | Feb 9, 2026 | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properl... |
| CVE-2025-66600 | HIGH | 8.8 | 0.3% | Feb 9, 2026 | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product lacks HSTS (HTTP... |
| CVE-2025-15100 | HIGH | 8.8 | 0.3% | Feb 8, 2026 | The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including... |
| CVE-2025-68621 | HIGH | 7.4 | 0.5% | Feb 6, 2026 | Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large person... |
| CVE-2025-69214 | HIGH | 8.8 | 0.4% | Feb 6, 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an SQ... |
| CVE-2025-69212 | HIGH | 8.8 | 1.8% | Feb 6, 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a cri... |
| CVE-2025-70963 | HIGH | 7.6 | 0.3% | Feb 6, 2026 | Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived ... |
| CVE-2025-64175 | HIGH | 8.8 | 0.4% | Feb 6, 2026 | Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not... |
| CVE-2025-15566 | HIGH | 8.8 | 0.5% | Feb 6, 2026 | A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress ... |
| CVE-2025-15330 | HIGH | 8.8 | 0.3% | Feb 5, 2026 | Tanium addressed an improper input validation vulnerability in Deploy. |
| CVE-2025-15312 | HIGH | 7.2 | 0.3% | Feb 5, 2026 | Tanium addressed an improper output sanitization vulnerability in Tanium Appliance. |
| CVE-2025-15311 | HIGH | 7.8 | 0.2% | Feb 5, 2026 | Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance. |
| CVE-2025-70073 | HIGH | 7.2 | 0.7% | Feb 5, 2026 | An issue in ChestnutCMS v.1.5.8 and before allows a remote attacker to execute arbitrary code via the template creation ... |
| CVE-2025-15557 | HIGH | 8.8 | 0.2% | Feb 5, 2026 | An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on ... |
| CVE-2025-69906 | HIGH | 8.8 | 0.7% | Feb 5, 2026 | Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies o... |
| CVE-2025-68722 | HIGH | 8.8 | 0.2% | Feb 5, 2026 | Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability i... |
| CVE-2025-68721 | HIGH | 8.1 | 0.3% | Feb 5, 2026 | Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegat... |
| CVE-2025-13379 | HIGH | 8.6 | 0.4% | Feb 5, 2026 | IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ... |
| CVE-2025-15080 | HIGH | 8.8 | 0.5% | Feb 5, 2026 | Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric MELSEC iQ-R Series R08PCPU, R16P... |
| CVE-2025-61732 | HIGH | 8.6 | 0.5% | Feb 5, 2026 | A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. |
| CVE-2025-10314 | HIGH | 8.8 | 0.1% | Feb 5, 2026 | Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation FREQSHIP-mini for Windows versions 8.0.0 ... |
| CVE-2025-11730 | HIGH | 7.2 | 1.4% | Feb 5, 2026 | A post‑authentication command injection vulnerability in the Dynamic DNS (DDNS) configuration CLI command in Zyxel ATP s... |
| CVE-2025-13192 | HIGH | 8.2 | 0.4% | Feb 5, 2026 | The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPr... |
| CVE-2025-15555 | HIGH | 8.2 | 0.5% | Feb 4, 2026 | A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function hss_ogs_diam_... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now