2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58455 | HIGH | 8 | 0.4% | Feb 3, 2026 | Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a... |
| CVE-2025-58077 | HIGH | 8 | 0.4% | Feb 3, 2026 | Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a... |
| CVE-2025-52631 | HIGH | 8.1 | 0.2% | Feb 3, 2026 | HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability. This can allow... |
| CVE-2025-52628 | HIGH | 8.8 | 0.2% | Feb 3, 2026 | HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to ... |
| CVE-2025-70841 | HIGH | 7.5 | 0.4% | Feb 3, 2026 | Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive app... |
| CVE-2025-70758 | HIGH | 7.5 | 0.6% | Feb 3, 2026 | chetans9 core-php-admin-panel through commit a94a780d6 contains an authentication bypass vulnerability in includes/auth_... |
| CVE-2025-70560 | HIGH | 8.4 | 0.1% | Feb 3, 2026 | Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application us... |
| CVE-2025-69875 | HIGH | 7.8 | 0.1% | Feb 3, 2026 | A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient val... |
| CVE-2025-66374 | HIGH | 7.8 | 0.2% | Feb 3, 2026 | CyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through po... |
| CVE-2025-62599 | HIGH | 7.5 | 0.4% | Feb 3, 2026 | eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management ... |
| CVE-2025-60865 | HIGH | 7.8 | 0.1% | Feb 3, 2026 | Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate priv... |
| CVE-2025-59439 | HIGH | 7.5 | 0.4% | Feb 3, 2026 | An issue was discovered in Samsung Mobile Processor, Wearable Processor and Modem Exynos 980, 990, 850, 1080, 9110, W920... |
| CVE-2025-52627 | HIGH | 7.5 | 0.1% | Feb 3, 2026 | Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critic... |
| CVE-2025-14550 | HIGH | 7.5 | 1.0% | Feb 3, 2026 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `ASGIRequest` allows a remote att... |
| CVE-2025-7760 | HIGH | 7.6 | 0.3% | Feb 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ofisimo Web... |
| CVE-2025-6397 | HIGH | 8.6 | 0.2% | Feb 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ankara Host... |
| CVE-2025-67853 | HIGH | 7.5 | 0.4% | Feb 3, 2026 | A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email ser... |
| CVE-2025-67851 | HIGH | 7.8 | 0.3% | Feb 3, 2026 | A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper esc... |
| CVE-2025-67848 | HIGH | 8.1 | 0.4% | Feb 3, 2026 | A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the ... |
| CVE-2025-59902 | HIGH | 7.1 | 0.3% | Feb 3, 2026 | HTML injection vulnerability in NICE Chat. This vulnerability allows an attacker to inject and render arbitrary HTML con... |
| CVE-2025-8461 | HIGH | 7.6 | 0.2% | Feb 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Seres Softw... |
| CVE-2025-8456 | HIGH | 7.6 | 0.2% | Feb 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kod8 Softwa... |
| CVE-2025-8590 | HIGH | 7.5 | 0.3% | Feb 3, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in AKCE Software Technology R&D Industry and Tr... |
| CVE-2025-8589 | HIGH | 7.6 | 0.3% | Feb 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AKCE Softwa... |
| CVE-2025-9711 | HIGH | 7.8 | 0.1% | Feb 3, 2026 | A vulnerability in Brocade Fabric OS before 9.2.1c3 could allow elevating the privileges of the local authenticated user... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now