2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27379 | MEDIUM | 4.6 | 0.2% | Jan 22, 2026 | A stored cross-site scripting (XSS) vulnerability in the BOM Viewer in Altium AES 7.0.3 allows an authenticated attacker... |
| CVE-2025-27377 | MEDIUM | 5.3 | 0.2% | Jan 22, 2026 | Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capa... |
| CVE-2025-69285 | MEDIUM | 6.1 | 0.4% | Jan 21, 2026 | SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.5.0 contain a mi... |
| CVE-2025-69209 | MEDIUM | 6.9 | 0.1% | Jan 21, 2026 | ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in ... |
| CVE-2025-68140 | MEDIUM | 4.3 | 0.1% | Jan 21, 2026 | EVerest is an EV charging software stack. Prior to version 2025.9.0, once the validity of the received V2G message has b... |
| CVE-2025-68139 | MEDIUM | 4.3 | 0.1% | Jan 21, 2026 | EVerest is an EV charging software stack. In all versions up to and including 2025.12.1, the default value for `terminat... |
| CVE-2025-68138 | MEDIUM | 4.7 | 0.2% | Jan 21, 2026 | EVerest is an EV charging software stack, and EVerest libocpp is a C++ implementation of the Open Charge Point Protocol.... |
| CVE-2025-13465 | MEDIUM | 5.3 | 1.5% | Jan 21, 2026 | Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An atta... |
| CVE-2025-12781 | MEDIUM | 5.3 | 0.5% | Jan 21, 2026 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the... |
| CVE-2025-68135 | MEDIUM | 6.5 | 0.3% | Jan 21, 2026 | EVerest is an EV charging software stack. Prior to version 2025.10.0, C++ exceptions are not properly handled for and by... |
| CVE-2025-68132 | MEDIUM | 4.6 | 0.2% | Jan 21, 2026 | EVerest is an EV charging software stack. Prior to version 2025.12.0, `is_message_crc_correct` in the DZG_GSH01 powermet... |
| CVE-2025-57681 | MEDIUM | 5.4 | 0.2% | Jan 21, 2026 | The WorklogPRO - Timesheets for Jira plugin in Jira Data Center before version 4.23.6-jira10 and before version 4.23.5-j... |
| CVE-2025-14559 | MEDIUM | 6.5 | 0.4% | Jan 21, 2026 | A flaw was found in the keycloak-services component of Keycloak. This vulnerability allows the issuance of access and re... |
| CVE-2025-58742 | MEDIUM | 5.9 | 0.2% | Jan 20, 2026 | Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability ... |
| CVE-2025-58740 | MEDIUM | 5.5 | 0.1% | Jan 20, 2026 | The use of a hard-coded encryption key in calls to the Password function in C2SGlobalSettings.dll in Milner ImageDirecto... |
| CVE-2025-15367 | MEDIUM | 5.9 | 0.3% | Jan 20, 2026 | The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigati... |
| CVE-2025-15366 | MEDIUM | 5.9 | 0.4% | Jan 20, 2026 | The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigat... |
| CVE-2025-15282 | MEDIUM | 6 | 0.5% | Jan 20, 2026 | User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL ... |
| CVE-2025-11468 | MEDIUM | 5.7 | 0.5% | Jan 20, 2026 | When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not b... |
| CVE-2025-55132 | MEDIUM | 5.3 | 0.2% | Jan 20, 2026 | A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` ev... |
| CVE-2025-66803 | MEDIUM | 4.8 | 0.2% | Jan 20, 2026 | Race condition in the turbo-frame element handler in Hotwired Turbo before 8.0.x causes logout operations to fail when d... |
| CVE-2025-67263 | MEDIUM | 6.1 | 0.2% | Jan 20, 2026 | Abacre Retail Point of Sale 14.0.0.396 is affected by a stored cross-site scripting (XSS) vulnerability in the Clients m... |
| CVE-2025-67261 | MEDIUM | 6.5 | 0.2% | Jan 20, 2026 | Abacre Retail Point of Sale 14.0.0.396 is vulnerable to content-based blind SQL injection. The vulnerability exists in t... |
| CVE-2025-33231 | MEDIUM | 6.7 | 0.2% | Jan 20, 2026 | NVIDIA Nsight Systems for Windows contains a vulnerability in the application’s DLL loading mechanism where an attacker ... |
| CVE-2025-67824 | MEDIUM | 6.1 | 0.2% | Jan 20, 2026 | The WorklogPRO - Jira Timesheets plugin in the Jira Data Center before 4.24.2-jira9, 4.24.2-jira10 and 4.24.2-jira11 all... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now