2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36184 | HIGH | 7.2 | 0.5% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 could allow an instance owner to execu... |
| CVE-2025-36070 | HIGH | 7.5 | 0.4% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to ... |
| CVE-2025-11175 | HIGH | 8.8 | 0.4% | Jan 30, 2026 | Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') v... |
| CVE-2025-69662 | HIGH | 8.6 | 0.4% | Jan 30, 2026 | SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_po... |
| CVE-2025-62349 | HIGH | 7.5 | 0.4% | Jan 30, 2026 | Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer au... |
| CVE-2025-62348 | HIGH | 7.8 | 0.2% | Jan 30, 2026 | Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by ... |
| CVE-2025-4686 | HIGH | 8.6 | 0.3% | Jan 30, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kodmatic Computer ... |
| CVE-2025-13176 | HIGH | 8.4 | 0.2% | Jan 30, 2026 | Planting a custom configuration file in ESET Inspect Connector allow load a malicious DLL. |
| CVE-2025-1395 | HIGH | 8.2 | 0.3% | Jan 30, 2026 | Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technolog... |
| CVE-2025-69604 | HIGH | 7.8 | 0.1% | Jan 29, 2026 | An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to in... |
| CVE-2025-69516 | HIGH | 8.8 | 2.1% | Jan 29, 2026 | A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactica... |
| CVE-2025-63658 | HIGH | 7.5 | 1.1% | Jan 29, 2026 | A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to... |
| CVE-2025-63657 | HIGH | 7.5 | 1.0% | Jan 29, 2026 | An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attacke... |
| CVE-2025-63656 | HIGH | 7.5 | 1.0% | Jan 29, 2026 | An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers ... |
| CVE-2025-63655 | HIGH | 7.5 | 7.4% | Jan 29, 2026 | A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows att... |
| CVE-2025-63653 | HIGH | 7.5 | 1.0% | Jan 29, 2026 | An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attacker... |
| CVE-2025-63652 | HIGH | 7.5 | 1.0% | Jan 29, 2026 | A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to ... |
| CVE-2025-63651 | HIGH | 7.5 | 0.9% | Jan 29, 2026 | A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers t... |
| CVE-2025-63650 | HIGH | 7.5 | 1.0% | Jan 29, 2026 | An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers t... |
| CVE-2025-63649 | HIGH | 7.5 | 1.0% | Jan 29, 2026 | An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commi... |
| CVE-2025-13399 | HIGH | 8.8 | 0.2% | Jan 29, 2026 | A weakness in the web interface’s application layer encryption in VX800v v1.0 allows an adjacent attacker to brute force... |
| CVE-2025-62514 | HIGH | 7.1 | 0.3% | Jan 29, 2026 | Parsec is a cloud-based application for cryptographically secure file sharing. In versions on the 3.x branch prior to 3.... |
| CVE-2025-13905 | HIGH | 7 | 0.1% | Jan 29, 2026 | CWE-276: Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the reverse s... |
| CVE-2025-7014 | HIGH | 8.8 | 0.3% | Jan 29, 2026 | Session Fixation vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Session Hijacking. This issue affect... |
| CVE-2025-14975 | HIGH | 8.1 | 0.3% | Jan 29, 2026 | The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now