2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55704 | MEDIUM | 6.9 | 0.2% | Jan 29, 2026 | Hidden functionality issue exists in multiple MFPs provided by Brother Industries, Ltd., which may allow an attacker to ... |
| CVE-2025-53869 | MEDIUM | 6.3 | 0.1% | Jan 29, 2026 | Multiple MFPs provided by Brother Industries, Ltd. does not properly validate server certificates, which may allow a man... |
| CVE-2025-71006 | MEDIUM | 6.5 | 0.3% | Jan 28, 2026 | A floating point exception (FPE) in the oneflow.reshape component of OneFlow v0.9.0 allows attackers to cause a Denial o... |
| CVE-2025-71005 | MEDIUM | 6.5 | 0.2% | Jan 28, 2026 | A floating point exception (FPE) in the oneflow.view component of OneFlow v0.9.0 allows attackers to cause a Denial of S... |
| CVE-2025-71004 | MEDIUM | 6.5 | 0.2% | Jan 28, 2026 | A segmentation violation in the oneflow.logical_or component of OneFlow v0.9.0 allows attackers to cause a Denial of Ser... |
| CVE-2025-71002 | MEDIUM | 6.5 | 0.3% | Jan 28, 2026 | A floating-point exception (FPE) in the flow.column_stack component of OneFlow v0.9.0 allows attackers to cause a Denial... |
| CVE-2025-69289 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | Discourse is an open source discussion platform. A privilege escalation vulnerability in versions prior to 3.5.4, 2025.1... |
| CVE-2025-69218 | MEDIUM | 6.5 | 0.2% | Jan 28, 2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderat... |
| CVE-2025-68934 | MEDIUM | 6.5 | 0.2% | Jan 28, 2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, authent... |
| CVE-2025-68933 | MEDIUM | 5.4 | 0.1% | Jan 28, 2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-adm... |
| CVE-2025-68666 | MEDIUM | 6.5 | 0.2% | Jan 28, 2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, users a... |
| CVE-2025-61730 | MEDIUM | 5.3 | 0.3% | Jan 28, 2026 | During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instanc... |
| CVE-2025-61728 | MEDIUM | 6.5 | 0.6% | Jan 28, 2026 | archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is open... |
| CVE-2025-13986 | MEDIUM | 4.2 | 0.2% | Jan 28, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality... |
| CVE-2025-13985 | MEDIUM | 5.3 | 0.2% | Jan 28, 2026 | Incorrect Authorization vulnerability in Drupal Entity Share allows Forceful Browsing.This issue affects Entity Share: f... |
| CVE-2025-13984 | MEDIUM | 6.1 | 0.1% | Jan 28, 2026 | Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js allows Cross-Site Scripti... |
| CVE-2025-13983 | MEDIUM | 5.4 | 0.1% | Jan 28, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allo... |
| CVE-2025-13981 | MEDIUM | 4.4 | 0.1% | Jan 28, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI (Artific... |
| CVE-2025-13980 | MEDIUM | 5.3 | 0.2% | Jan 28, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CKEditor 5 Premium Features allows Func... |
| CVE-2025-13979 | MEDIUM | 5.4 | 0.1% | Jan 28, 2026 | Privilege Defined With Unsafe Actions vulnerability in Drupal Mini site allows Stored XSS.This issue affects Mini site: ... |
| CVE-2025-71001 | MEDIUM | 6.5 | 0.4% | Jan 28, 2026 | A segmentation violation in the flow.column_stack component of OneFlow v0.9.0 allows attackers to cause a Denial of Serv... |
| CVE-2025-69601 | MEDIUM | 6.5 | 0.6% | Jan 28, 2026 | A directory traversal (Zip Slip) vulnerability exists in the “Static Sites” feature of 66biolinks v44.0.0 by AltumCode. ... |
| CVE-2025-68660 | MEDIUM | 5.4 | 0.2% | Jan 28, 2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, an endp... |
| CVE-2025-68659 | MEDIUM | 5.3 | 0.2% | Jan 28, 2026 | Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have an app... |
| CVE-2025-68479 | MEDIUM | 5.3 | 0.2% | Jan 28, 2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, some su... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now