2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15497 | LOW | 3.8 | 0.3% | Jan 30, 2026 | Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigge... |
| CVE-2025-9615 | LOW | 3.3 | 0.2% | Jan 26, 2026 | A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. Ne... |
| CVE-2025-57784 | LOW | 3.3 | 0.1% | Jan 26, 2026 | Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows... |
| CVE-2025-71148 | LOW | 3.3 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/handshake: restore destructor on submit failure... |
| CVE-2025-47555 | LOW | 3.8 | 0.3% | Jan 22, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly ... |
| CVE-2025-12738 | LOW | 1.3 | 0.4% | Jan 22, 2026 | Neo4j Enterprise edition versions prior to 2025.11.2 and 5.26.17 are vulnerable to a potential information disclosure by... |
| CVE-2025-14083 | LOW | 2.7 | 0.3% | Jan 21, 2026 | A flaw was found in the Keycloak Admin REST API. This vulnerability allows the exposure of backend schema and rules, pot... |
| CVE-2025-36411 | LOW | 3.5 | 0.1% | Jan 20, 2026 | IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau... |
| CVE-2025-15535 | LOW | 3.3 | 0.1% | Jan 18, 2026 | A security flaw has been discovered in nicbarker clay up to 0.14. This affects the function Clay__MeasureTextCached in t... |
| CVE-2025-61873 | LOW | 2.6 | 0.2% | Jan 16, 2026 | Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV expor... |
| CVE-2025-31186 | LOW | 3.3 | 0.1% | Jan 16, 2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to... |
| CVE-2025-24090 | LOW | 3.3 | 0.1% | Jan 16, 2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app ... |
| CVE-2025-14058 | LOW | 3.2 | 0.1% | Jan 14, 2026 | A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized us... |
| CVE-2025-67685 | LOW | 3.8 | 0.4% | Jan 13, 2026 | A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4,... |
| CVE-2025-58409 | LOW | 3.5 | 0.1% | Jan 13, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to ... |
| CVE-2025-15506 | LOW | 3.3 | 0.2% | Jan 11, 2026 | A vulnerability was found in AcademySoftwareFoundation OpenColorIO up to 2.5.0. This issue affects the function ConvertT... |
| CVE-2025-15505 | LOW | 2.4 | 0.2% | Jan 11, 2026 | A vulnerability was found in Luxul XWR-600 up to 4.0.1. The affected element is an unknown function of the component Web... |
| CVE-2025-53470 | LOW | 3.1 | 0.3% | Jan 10, 2026 | Out-of-bounds Read vulnerability in Apache NimBLE HCI H4 driver. Specially crafted HCI event could lead to invalid memo... |
| CVE-2025-62487 | LOW | 3.5 | 0.2% | Jan 9, 2026 | On October 1, 2025, Palantir discovered that images uploaded through the Dossier front-end app were not being marked cor... |
| CVE-2025-3950 | LOW | 3.5 | 0.2% | Jan 9, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 1... |
| CVE-2025-15224 | LOW | 3.1 | 0.4% | Jan 8, 2026 | When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly s... |
| CVE-2025-62224 | LOW | 3.5 | 0.3% | Jan 7, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacke... |
| CVE-2025-31963 | LOW | 3.3 | 0.1% | Jan 7, 2026 | Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2... |
| CVE-2025-12958 | LOW | 2.7 | 0.2% | Jan 7, 2026 | The Rankology SEO and Analytics Tool plugin for WordPress is vulnerable to unauthorized modification of data due to an i... |
| CVE-2025-9543 | LOW | 3.5 | 0.2% | Jan 5, 2026 | The FlexTable WordPress plugin before 3.19.2 does not sanitise and escape the imported links from Google Sheet cells, w... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now