2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71020 | HIGH | 7.5 | 0.3% | Jan 16, 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_4C408 function. T... |
| CVE-2025-70746 | HIGH | 7.5 | 0.4% | Jan 16, 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the timeZone parameter of the fromSetSysTime functi... |
| CVE-2025-68921 | HIGH | 7.8 | 0.3% | Jan 16, 2026 | SteelSeries Nahimic 3 1.10.7 allows Directory traversal. |
| CVE-2025-68675 | HIGH | 7.5 | 2.0% | Jan 16, 2026 | In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy U... |
| CVE-2025-68438 | HIGH | 7.5 | 0.6% | Jan 16, 2026 | In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length... |
| CVE-2025-14844 | HIGH | 7.5 | 0.4% | Jan 16, 2026 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up... |
| CVE-2025-12007 | HIGH | 8.4 | 0.1% | Jan 16, 2026 | There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can up... |
| CVE-2025-12006 | HIGH | 7.2 | 0.3% | Jan 16, 2026 | There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW-F . An attacker can up... |
| CVE-2025-12957 | HIGH | 8.8 | 0.6% | Jan 16, 2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and incl... |
| CVE-2025-65117 | HIGH | 7.7 | 0.2% | Jan 16, 2026 | The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed O... |
| CVE-2025-64769 | HIGH | 7.6 | 0.2% | Jan 16, 2026 | The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted an... |
| CVE-2025-64729 | HIGH | 8.2 | 0.2% | Jan 16, 2026 | The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optim... |
| CVE-2025-61943 | HIGH | 7.8 | 0.3% | Jan 16, 2026 | The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper ... |
| CVE-2025-67823 | HIGH | 8.2 | 0.3% | Jan 15, 2026 | A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX thro... |
| CVE-2025-70893 | HIGH | 8.8 | 0.4% | Jan 15, 2026 | A time-based blind SQL Injection vulnerability exists in PHPGurukul Cyber Cafe Management System v1.0 within the adminpr... |
| CVE-2025-60003 | HIGH | 8.7 | 0.4% | Jan 15, 2026 | A Buffer Over-read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved ... |
| CVE-2025-59960 | HIGH | 7.4 | 0.2% | Jan 15, 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (jdhcpd) of Juniper Ne... |
| CVE-2025-13845 | HIGH | 7.8 | 0.3% | Jan 15, 2026 | CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious pro... |
| CVE-2025-9014 | HIGH | 7.5 | 0.4% | Jan 15, 2026 | A Null Pointer Dereference vulnerability exists in the referer header check of the web portal of TP-Link TL-WR841N v14, ... |
| CVE-2025-70307 | HIGH | 7.5 | 0.4% | Jan 15, 2026 | A stack overflow in the dump_ttxt_sample function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via... |
| CVE-2025-36911 | HIGH | 7.1 | 6.9% | Jan 15, 2026 | In key-based pairing, there is a possible ID due to a logic error in the code. This could lead to remote (proximal/adjac... |
| CVE-2025-70656 | HIGH | 7.5 | 0.3% | Jan 15, 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the mac parameter of the sub_65B5C function. This v... |
| CVE-2025-70308 | HIGH | 7.5 | 0.3% | Jan 15, 2026 | An out-of-bounds read in the GSF demuxer filter component of GPAC v2.4.0 allows attackers to cause a Denial of Service (... |
| CVE-2025-70304 | HIGH | 7.5 | 0.3% | Jan 15, 2026 | A buffer overflow in the vobsub_get_subpic_duration() function of GPAC v2.4.0 allows attackers to cause a Denial of Serv... |
| CVE-2025-70298 | HIGH | 8.2 | 0.4% | Jan 15, 2026 | GPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmx_parse_tags function. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now