2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59473 | HIGH | 7.2 | 0.3% | Jan 26, 2026 | SQL Injection vulnerability in the Structure for Admin authenticated user |
| CVE-2025-59472 | HIGH | 7.5 | 0.4% | Jan 26, 2026 | A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in min... |
| CVE-2025-59471 | HIGH | 7.5 | 0.4% | Jan 26, 2026 | A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for t... |
| CVE-2025-14459 | HIGH | 8.5 | 0.4% | Jan 26, 2026 | A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolu... |
| CVE-2025-14756 | HIGH | 8.8 | 2.7% | Jan 26, 2026 | Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing... |
| CVE-2025-71178 | HIGH | 7.1 | 0.2% | Jan 26, 2026 | Crucial Storage Executive installer versions prior to 11.08.082025.00 contain a DLL preloading vulnerability. During ins... |
| CVE-2025-67274 | HIGH | 7.5 | 0.4% | Jan 26, 2026 | An issue in continuous.software aangine v.2025.2 allows a remote attacker to obtain sensitive information via the excel-... |
| CVE-2025-59107 | HIGH | 8.5 | 0.2% | Jan 26, 2026 | Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The... |
| CVE-2025-59106 | HIGH | 8.8 | 0.7% | Jan 26, 2026 | The binary serving the web server and executing basically all actions launched from the Web UI is running with root priv... |
| CVE-2025-59105 | HIGH | 7 | 0.1% | Jan 26, 2026 | With physical access to the device and enough time an attacker can desolder the flash memory, modify it and then reinsta... |
| CVE-2025-59104 | HIGH | 7 | 0.2% | Jan 26, 2026 | With physical access to the device and enough time an attacker is able to solder test leads to the debug footprint (or u... |
| CVE-2025-59101 | HIGH | 7.7 | 0.6% | Jan 26, 2026 | Instead of typical session tokens or cookies, it is verified on a per-request basis if the originating IP address has on... |
| CVE-2025-59099 | HIGH | 8.8 | 0.7% | Jan 26, 2026 | The Access Manager is using the open source web server CompactWebServer written in C#. This web server is affected by a ... |
| CVE-2025-59098 | HIGH | 8.7 | 0.3% | Jan 26, 2026 | The Access Manager is offering a trace functionality to debug errors and issues with the device. The trace functionality... |
| CVE-2025-59094 | HIGH | 8.4 | 0.2% | Jan 26, 2026 | A local privilege escalation vulnerability has been identified in the Kaba exos 9300 System management application (d9sy... |
| CVE-2025-59093 | HIGH | 8.5 | 0.2% | Jan 26, 2026 | Exos 9300 instances are using a randomly generated database password to connect to the configured MSSQL server. The pass... |
| CVE-2025-59092 | HIGH | 8.7 | 0.8% | Jan 26, 2026 | An RPC service, which is part of exos 9300, is reachable on port 4000, run by the process FSMobilePhoneInterface.exe. Th... |
| CVE-2025-27821 | HIGH | 7.3 | 0.9% | Jan 26, 2026 | Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client. This issue affects Apache Hadoop: from 3.2.0 bef... |
| CVE-2025-14316 | HIGH | 7.1 | 0.2% | Jan 26, 2026 | The AhaChat Messenger Marketing WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting ... |
| CVE-2025-71162 | HIGH | 7.8 | 0.2% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: tegra-adma: Fix use-after-free A use-af... |
| CVE-2025-52026 | HIGH | 7.5 | 0.3% | Jan 23, 2026 | An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend... |
| CVE-2025-67264 | HIGH | 7.8 | 0.9% | Jan 23, 2026 | An OS command injection vulnerability in the com.sprd.engineermode component in Doogee Note59, Note59 Pro, and Note59 Pr... |
| CVE-2025-70986 | HIGH | 7.5 | 0.4% | Jan 23, 2026 | Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access ... |
| CVE-2025-67230 | HIGH | 7.1 | 0.2% | Jan 23, 2026 | Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0.33.0 allows attackers with rendere... |
| CVE-2025-71159 | HIGH | 7.8 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free warning in btrfs_get_or_c... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now