2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-57283 | HIGH | 7.8 | 0.7% | Jan 28, 2026 | The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile... |
| CVE-2025-59901 | HIGH | 8.5 | 0.2% | Jan 28, 2026 | Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoin... |
| CVE-2025-59895 | HIGH | 7.5 | 0.4% | Jan 28, 2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a remote denial-of-service (DoS) vulne... |
| CVE-2025-59894 | HIGH | 8 | 0.1% | Jan 28, 2026 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.... |
| CVE-2025-59893 | HIGH | 8 | 0.1% | Jan 28, 2026 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.... |
| CVE-2025-59892 | HIGH | 8 | 0.1% | Jan 28, 2026 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.... |
| CVE-2025-59891 | HIGH | 8 | 0.1% | Jan 28, 2026 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.... |
| CVE-2025-26386 | HIGH | 7.1 | 0.4% | Jan 28, 2026 | Johnson Controls iSTAR Configuration Utility (ICU) has Stack-based Buffer Overflow vulnerability. This issue affects iST... |
| CVE-2025-14386 | HIGH | 8.8 | 0.4% | Jan 28, 2026 | The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress ... |
| CVE-2025-7740 | HIGH | 8.8 | 0.2% | Jan 28, 2026 | Default credentials vulnerability exists in SuprOS product. If exploited, this could allow an authenticated local attack... |
| CVE-2025-40537 | HIGH | 7.5 | 0.5% | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situat... |
| CVE-2025-14610 | HIGH | 7.2 | 0.3% | Jan 28, 2026 | The TableMaster for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a... |
| CVE-2025-67645 | HIGH | 8.8 | 0.3% | Jan 28, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ... |
| CVE-2025-55292 | HIGH | 8.2 | 0.1% | Jan 28, 2026 | Meshtastic is an open source mesh networking solution. In the current Meshtastic architecture, a Node is identified by t... |
| CVE-2025-33234 | HIGH | 7.8 | 0.2% | Jan 27, 2026 | NVIDIA runx contains a vulnerability where an attacker could cause a code injection. A successful exploit of this vulner... |
| CVE-2025-14911 | HIGH | 7.1 | 0.3% | Jan 27, 2026 | User-controlled chunkSize metadata from MongoDB lacks appropriate validation allowing malformed GridFS metadata to overf... |
| CVE-2025-69421 | HIGH | 7.5 | 0.8% | Jan 27, 2026 | Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i... |
| CVE-2025-69420 | HIGH | 7.5 | 0.8% | Jan 27, 2026 | Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE unio... |
| CVE-2025-69419 | HIGH | 7.4 | 0.4% | Jan 27, 2026 | Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16... |
| CVE-2025-55102 | HIGH | 7.5 | 0.4% | Jan 27, 2026 | A denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A special... |
| CVE-2025-55095 | HIGH | 7 | 0.1% | Jan 27, 2026 | The function _ux_host_class_storage_media_mount() is responsible for mounting partitions on a USB mass storage device. W... |
| CVE-2025-15467 | HIGH | 8.8 | 47.6% | Jan 27, 2026 | Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigg... |
| CVE-2025-41727 | HIGH | 7.8 | 0.2% | Jan 27, 2026 | A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to per... |
| CVE-2025-41726 | HIGH | 8.8 | 0.4% | Jan 27, 2026 | A low privileged remote attacker can execute arbitrary code by sending specially crafted calls to the web service of the... |
| CVE-2025-30248 | HIGH | 8.9 | 0.6% | Jan 26, 2026 | DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now