2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69908 | HIGH | 7.5 | 0.4% | Jan 23, 2026 | An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged... |
| CVE-2025-66720 | HIGH | 7.5 | 0.4% | Jan 23, 2026 | Null pointer dereference in free5gc pcf 1.4.0 in file internal/sbi/processor/ampolicy.go in function HandleDeletePolicie... |
| CVE-2025-71157 | HIGH | 7.8 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: always drop device refcount in ib_del_su... |
| CVE-2025-71156 | HIGH | 7.8 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: gve: defer interrupt enabling until NAPI registrati... |
| CVE-2025-71155 | HIGH | 7.8 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix gmap_helper_zap_one_page() again A ... |
| CVE-2025-71152 | HIGH | 7.8 | 0.1% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: dsa: properly keep track of conduit reference ... |
| CVE-2025-69907 | HIGH | 7.5 | 0.5% | Jan 23, 2026 | An unauthenticated information disclosure vulnerability exists in Newgen OmniDocs due to missing authentication and acce... |
| CVE-2025-71145 | HIGH | 7.8 | 0.2% | Jan 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: phy: isp1301: fix non-OF device reference imba... |
| CVE-2025-14866 | HIGH | 8.8 | 0.4% | Jan 23, 2026 | The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin... |
| CVE-2025-67847 | HIGH | 8.8 | 0.5% | Jan 23, 2026 | A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbi... |
| CVE-2025-3839 | HIGH | 8 | 0.4% | Jan 23, 2026 | A flaw was found in Epiphany, a tool that allows websites to open external URL handler applications with minimal user in... |
| CVE-2025-15351 | HIGH | 7.8 | 0.3% | Jan 23, 2026 | Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerab... |
| CVE-2025-15350 | HIGH | 7.8 | 0.3% | Jan 23, 2026 | Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerab... |
| CVE-2025-15349 | HIGH | 7.5 | 0.4% | Jan 23, 2026 | Anritsu ShockLine SCPI Race Condition Remote Code Execution Vulnerability. This vulnerability allows network-adjacent at... |
| CVE-2025-15348 | HIGH | 7.8 | 0.3% | Jan 23, 2026 | Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerabi... |
| CVE-2025-15062 | HIGH | 7.8 | 0.3% | Jan 23, 2026 | Trimble SketchUp SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2025-15059 | HIGH | 7.8 | 0.7% | Jan 23, 2026 | GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2025-11002 | HIGH | 7.8 | 0.5% | Jan 23, 2026 | 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attacke... |
| CVE-2025-53968 | HIGH | 7.5 | 0.4% | Jan 22, 2026 | This vulnerability arises because there are no limitations on the number of authentication attempts a user can make. An... |
| CVE-2025-14751 | HIGH | 8.7 | 0.4% | Jan 22, 2026 | A low-privileged user can bypass account credentials without confirming the user's current authentication state, which m... |
| CVE-2025-14750 | HIGH | 8.7 | 0.3% | Jan 22, 2026 | The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally con... |
| CVE-2025-66428 | HIGH | 8.8 | 0.4% | Jan 22, 2026 | An issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation. |
| CVE-2025-69321 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand S... |
| CVE-2025-69320 | HIGH | 7.1 | 0.2% | Jan 22, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand M... |
| CVE-2025-69319 | HIGH | 7.5 | 0.3% | Jan 22, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Beaver Builder Beaver Builder beaver-builder-... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now