2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14377 | HIGH | 8.8 | 0.2% | Jan 20, 2026 | A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager, caused by plaintext... |
| CVE-2025-14376 | HIGH | 8.6 | 0.1% | Jan 20, 2026 | A security issue was discovered within the legacy ADI server component of Verve Asset Manager, caused by plaintext secre... |
| CVE-2025-14027 | HIGH | 8.7 | 0.4% | Jan 20, 2026 | Multiple denial-of-service vulnerabilities exist in the affected product. These issues can be triggered through various ... |
| CVE-2025-11743 | HIGH | 7.1 | 0.2% | Jan 20, 2026 | A denial-of-service security issue in the affected product. The security issue occurs when a malformed CIP forward open ... |
| CVE-2025-14977 | HIGH | 8.1 | 0.3% | Jan 20, 2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPr... |
| CVE-2025-52659 | HIGH | 7.5 | 0.2% | Jan 19, 2026 | HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensit... |
| CVE-2025-68616 | HIGH | 7.5 | 0.5% | Jan 19, 2026 | WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) pro... |
| CVE-2025-61684 | HIGH | 7.5 | 0.3% | Jan 19, 2026 | Quicly, an IETF QUIC protocol implementation, is susceptible to a denial-of-service attack prior to commit d9d3df6a8530a... |
| CVE-2025-11044 | HIGH | 8.9 | 0.3% | Jan 19, 2026 | An Allocation of Resources Without Limits or Throttling vulnerability in the ANSL-Server component of B&R Automation Run... |
| CVE-2025-29847 | HIGH | 7.5 | 0.7% | Jan 19, 2026 | A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and ... |
| CVE-2025-15539 | HIGH | 7.5 | 0.7% | Jan 19, 2026 | A vulnerability was determined in Open5GS up to 2.7.6. Impacted is the function sgwc_s11_handle_downlink_data_notificati... |
| CVE-2025-15538 | HIGH | 7.8 | 0.2% | Jan 18, 2026 | A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. Affected by this vulnerabili... |
| CVE-2025-15534 | HIGH | 7.8 | 0.2% | Jan 18, 2026 | A vulnerability was identified in raysan5 raylib up to 909f040. Affected by this issue is the function LoadFontData of t... |
| CVE-2025-15533 | HIGH | 7.8 | 0.3% | Jan 18, 2026 | A vulnerability was determined in raysan5 raylib up to 909f040. Affected by this vulnerability is the function GenImageF... |
| CVE-2025-15532 | HIGH | 7.5 | 1.0% | Jan 17, 2026 | A security flaw has been discovered in Open5GS up to 2.7.5. This issue affects some unknown processing of the component ... |
| CVE-2025-15530 | HIGH | 7.5 | 0.7% | Jan 17, 2026 | A vulnerability was determined in Open5GS up to 2.7.6. This affects the function sgwc_s11_handle_create_indirect_data_fo... |
| CVE-2025-14478 | HIGH | 7.5 | 0.4% | Jan 17, 2026 | The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in all versions up to, ... |
| CVE-2025-15529 | HIGH | 7.5 | 0.7% | Jan 16, 2026 | A vulnerability was found in Open5GS up to 2.7.6. Affected by this issue is the function sgwc_s5c_handle_create_session_... |
| CVE-2025-15528 | HIGH | 7.5 | 0.8% | Jan 16, 2026 | A vulnerability has been found in Open5GS up to 2.7.6. Affected by this vulnerability is an unknown functionality of the... |
| CVE-2025-68924 | HIGH | 7.5 | 0.7% | Jan 16, 2026 | In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a... |
| CVE-2025-62291 | HIGH | 8.1 | 0.9% | Jan 16, 2026 | In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted ... |
| CVE-2025-48647 | HIGH | 7.8 | 0.1% | Jan 16, 2026 | In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc.c, there is a possible memory overwrite due to imprope... |
| CVE-2025-15032 | HIGH | 7.4 | 0.2% | Jan 16, 2026 | Missing about:blank indicator in custom-sized new windows in Dia before 1.9.0 on macOS could allow an attacker to spoof ... |
| CVE-2025-31510 | HIGH | 7.2 | 0.4% | Jan 16, 2026 | In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web... |
| CVE-2025-24528 | HIGH | 7.1 | 0.6% | Jan 16, 2026 | In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now