2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1060 | HIGH | 8.7 | 0.2% | Feb 13, 2025 | CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure of data ... |
| CVE-2025-1059 | HIGH | 8.7 | 0.4% | Feb 13, 2025 | CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause communications to st... |
| CVE-2025-1058 | HIGH | 8.1 | 0.2% | Feb 13, 2025 | CWE-494: Download of Code Without Integrity Check vulnerability exists that could render the device inoperable when mali... |
| CVE-2025-1227 | HIGH | 8.8 | 0.5% | Feb 12, 2025 | A vulnerability was found in ywoa up to 2024.07.03. It has been rated as critical. This issue affects the function selec... |
| CVE-2025-0110 | HIGH | 8.6 | 1.2% | Feb 12, 2025 | A command injection vulnerability in the Palo Alto Networks PAN-OS OpenConfig plugin enables an authenticated administra... |
| CVE-2025-1224 | HIGH | 8.8 | 0.4% | Feb 12, 2025 | A vulnerability classified as critical was found in ywoa up to 2024.07.03. This vulnerability affects the function listN... |
| CVE-2025-25283 | HIGH | 7.5 | 0.7% | Feb 12, 2025 | parse-duraton is software that allows users to convert a human readable duration to milliseconds. Versions prior to 2.1.... |
| CVE-2025-25205 | HIGH | 8.2 | 3.8% | Feb 12, 2025 | Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a ... |
| CVE-2025-1216 | HIGH | 8.8 | 0.5% | Feb 12, 2025 | A vulnerability, which was classified as critical, has been found in ywoa up to 2024.07.03. This issue affects the funct... |
| CVE-2025-1215 | HIGH | 7.8 | 0.5% | Feb 12, 2025 | A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of th... |
| CVE-2025-1146 | HIGH | 8.1 | 0.3% | Feb 12, 2025 | CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the... |
| CVE-2025-0937 | HIGH | 7.1 | 0.4% | Feb 12, 2025 | Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Poli... |
| CVE-2025-25200 | HIGH | 7.5 | 0.8% | Feb 12, 2025 | Koa is expressive middleware for Node.js using ES2017 async functions. Prior to versions 0.21.2, 1.7.1, 2.15.4, and 3.0.... |
| CVE-2025-25199 | HIGH | 7.5 | 1.3% | Feb 12, 2025 | go-crypto-winnative Go crypto backend for Windows using Cryptography API: Next Generation (CNG). Prior to commit f49c8e1... |
| CVE-2025-25198 | HIGH | 8.8 | 1.1% | Feb 12, 2025 | mailcow: dockerized is an open source groupware/email suite based on docker. Prior to version 2025-01a, a vulnerability ... |
| CVE-2025-1214 | HIGH | 8.8 | 0.6% | Feb 12, 2025 | A vulnerability classified as critical has been found in pihome-shc PiHome 2.0. This affects an unknown part of the file... |
| CVE-2025-25743 | HIGH | 7.2 | 1.8% | Feb 12, 2025 | D-Link DIR-853 A1 FW1.20B07 was discovered to contain a command injection vulnerability in the SetVirtualServerSettings ... |
| CVE-2025-1210 | HIGH | 8.8 | 0.4% | Feb 12, 2025 | A vulnerability classified as critical was found in code-projects Wazifa System 1.0. Affected by this vulnerability is a... |
| CVE-2025-1244 | HIGH | 8.8 | 2.6% | Feb 12, 2025 | A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execut... |
| CVE-2025-1212 | HIGH | 7.5 | 0.4% | Feb 12, 2025 | An information disclosure vulnerability in GitLab CE/EE affecting all versions from 8.3 prior to 17.6.5, 17.7 prior to 1... |
| CVE-2025-1206 | HIGH | 8.8 | 0.5% | Feb 12, 2025 | A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. This affects an unk... |
| CVE-2025-1042 | HIGH | 7.5 | 0.4% | Feb 12, 2025 | An insecure direct object reference vulnerability in GitLab EE affecting all versions from 15.7 prior to 17.6.5, 17.7 pr... |
| CVE-2025-26378 | HIGH | 8.8 | 0.5% | Feb 12, 2025 | A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 ... |
| CVE-2025-26377 | HIGH | 8.1 | 0.5% | Feb 12, 2025 | A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 ... |
| CVE-2025-26375 | HIGH | 8.8 | 0.5% | Feb 12, 2025 | A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now