2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68141 | HIGH | 7.4 | 0.2% | Jan 21, 2026 | EVerest is an EV charging software stack. Prior to version 2025.10.0, during the deserialization of a `DC_ChargeLoopRes`... |
| CVE-2025-68137 | HIGH | 8.3 | 0.3% | Jan 21, 2026 | EVerest is an EV charging software stack. Prior to version 2025.10.0, an integer overflow occurring in `SdpPacket::parse... |
| CVE-2025-68136 | HIGH | 7.4 | 0.3% | Jan 21, 2026 | EVerest is an EV charging software stack. Prior to version 2025.10.0, once the module receives a SDP request, it creates... |
| CVE-2025-68134 | HIGH | 7.4 | 0.2% | Jan 21, 2026 | EVerest is an EV charging software stack. Prior to version 2025.10.0, the use of the `assert` function to handle errors ... |
| CVE-2025-66960 | HIGH | 7.5 | 0.4% | Jan 21, 2026 | An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function rea... |
| CVE-2025-66959 | HIGH | 7.5 | 4.5% | Jan 21, 2026 | An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder |
| CVE-2025-70648 | HIGH | 7.5 | 0.3% | Jan 21, 2026 | Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security_5g parameter of the sub_727F4 function.... |
| CVE-2025-70646 | HIGH | 7.5 | 0.3% | Jan 21, 2026 | Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_72290 function. Th... |
| CVE-2025-70644 | HIGH | 7.5 | 0.3% | Jan 21, 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the time parameter of the sub_60CFC function. This ... |
| CVE-2025-70651 | HIGH | 7.5 | 0.3% | Jan 21, 2026 | Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow in the ssid parameter of the form_fast_setting_wifi_se... |
| CVE-2025-70650 | HIGH | 7.5 | 0.3% | Jan 21, 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the deviceList parameter of the formSetMacFilterCfg... |
| CVE-2025-70645 | HIGH | 7.5 | 0.3% | Jan 21, 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the deviceList parameter of the formSetWifiMacFilte... |
| CVE-2025-13878 | HIGH | 7.5 | 8.2% | Jan 21, 2026 | Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 thro... |
| CVE-2025-68133 | HIGH | 7.4 | 0.4% | Jan 21, 2026 | EVerest is an EV charging software stack. In versions 2025.9.0 and below, an attacker can exhaust the operating system's... |
| CVE-2025-58744 | HIGH | 7.5 | 0.1% | Jan 20, 2026 | Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in Milner ImageDirector Cap... |
| CVE-2025-58743 | HIGH | 7.5 | 0.1% | Jan 20, 2026 | Use of a Broken or Risky Cryptographic Algorithm (DES) vulnerability in the Password class in C2SConnections.dll in Mi... |
| CVE-2025-58741 | HIGH | 7.5 | 0.2% | Jan 20, 2026 | Insufficiently Protected Credentials vulnerability in the Credential Field of Milner ImageDirector Capture allows retrie... |
| CVE-2025-66902 | HIGH | 7.5 | 0.4% | Jan 20, 2026 | An input validation issue in in Pithikos websocket-server v.0.6.4 allows a remote attacker to obtain sensitive informati... |
| CVE-2025-66692 | HIGH | 7.5 | 0.3% | Jan 20, 2026 | A buffer over-read in the PublicKey::verify() method of Binance - Trust Wallet Core before commit 5668c67 allows attacke... |
| CVE-2025-63648 | HIGH | 7.5 | 0.3% | Jan 20, 2026 | A NULL pointer dereference in the dacp_reply_playqueueedit_move function (src/httpd_dacp.c) of owntone-server commit b7e... |
| CVE-2025-63647 | HIGH | 7.5 | 0.4% | Jan 20, 2026 | A NULL pointer dereference in the parse_meta function (src/httpd_daap.c) of owntone-server commit 334beb allows attacker... |
| CVE-2025-59466 | HIGH | 7.5 | 0.6% | Jan 20, 2026 | We have identified a bug in Node.js error handling where "Maximum call stack size exceeded" errors become uncatchable wh... |
| CVE-2025-59465 | HIGH | 7.5 | 3.8% | Jan 20, 2026 | A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unha... |
| CVE-2025-59464 | HIGH | 7.5 | 0.2% | Jan 20, 2026 | A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freein... |
| CVE-2025-57156 | HIGH | 7.5 | 0.4% | Jan 20, 2026 | NULL pointer dereference in the dacp_reply_playqueueedit_clear function in src/httpd_dacp.c in owntone-server through co... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now