2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68160 | MEDIUM | 4.7 | 0.2% | Jan 27, 2026 | Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO perf... |
| CVE-2025-66199 | MEDIUM | 5.9 | 0.4% | Jan 27, 2026 | Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decomp... |
| CVE-2025-28164 | MEDIUM | 5.5 | 0.1% | Jan 27, 2026 | Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_creat... |
| CVE-2025-28162 | MEDIUM | 5.5 | 0.1% | Jan 27, 2026 | Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngim... |
| CVE-2025-15469 | MEDIUM | 5.5 | 0.2% | Jan 27, 2026 | Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing al... |
| CVE-2025-15468 | MEDIUM | 5.9 | 0.7% | Jan 27, 2026 | Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an un... |
| CVE-2025-11187 | MEDIUM | 6.1 | 0.5% | Jan 27, 2026 | Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow... |
| CVE-2025-41728 | MEDIUM | 5.3 | 0.3% | Jan 27, 2026 | A low privileged remote attacker may be able to disclose confidential information from the memory of a privileged proces... |
| CVE-2025-12387 | MEDIUM | 6.9 | 0.7% | Jan 27, 2026 | A vulnerability in the Pix-Link LV-WR21Q router's language module allows remote attackers to trigger a denial of service... |
| CVE-2025-12386 | MEDIUM | 6.9 | 0.7% | Jan 27, 2026 | Pix-Link LV-WR21Q does not enforce any form of authentication for endpoint /goform/getHomePageInfo. Remote unauthenticat... |
| CVE-2025-14971 | MEDIUM | 5.3 | 0.3% | Jan 27, 2026 | The Link Invoice Payment for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to ... |
| CVE-2025-9820 | MEDIUM | 4 | 0.2% | Jan 26, 2026 | A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 tok... |
| CVE-2025-9522 | MEDIUM | 5.3 | 0.2% | Jan 26, 2026 | Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests t... |
| CVE-2025-9521 | MEDIUM | 6.5 | 0.3% | Jan 26, 2026 | Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypa... |
| CVE-2025-9520 | MEDIUM | 6.8 | 0.4% | Jan 26, 2026 | An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate r... |
| CVE-2025-14969 | MEDIUM | 4.3 | 0.4% | Jan 26, 2026 | A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client... |
| CVE-2025-14525 | MEDIUM | 6.4 | 0.3% | Jan 26, 2026 | A flaw was found in kubevirt. A user within a virtual machine (VM), if the guest agent is active, can exploit this by ca... |
| CVE-2025-11687 | MEDIUM | 6.1 | 0.3% | Jan 26, 2026 | A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page —... |
| CVE-2025-11065 | MEDIUM | 5.3 | 0.4% | Jan 26, 2026 | A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode... |
| CVE-2025-70368 | MEDIUM | 5.4 | 0.2% | Jan 26, 2026 | Worklenz version 2.1.5 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Project Updates feature. An att... |
| CVE-2025-57785 | MEDIUM | 6.5 | 0.3% | Jan 26, 2026 | A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which allows an unauthenticate... |
| CVE-2025-57783 | MEDIUM | 5.3 | 0.4% | Jan 26, 2026 | Improper header parsing may lead to request smuggling has been identified in Hiawatha webserver version 11.7 which allow... |
| CVE-2025-50537 | MEDIUM | 5.5 | 0.2% | Jan 26, 2026 | Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/sha... |
| CVE-2025-59109 | MEDIUM | 5.1 | 0.5% | Jan 26, 2026 | The dormakaba registration units 9002 (PIN Pad Units) have an exposed UART header on the backside. The PIN pad is sendin... |
| CVE-2025-59102 | MEDIUM | 6.9 | 0.3% | Jan 26, 2026 | The web server of the Access Manager offers a functionality to download a backup of the local database stored on the dev... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now