2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66292 | HIGH | 8.1 | 0.6% | Jan 15, 2026 | DPanel is an open source server management panel written in Go. Prior to 1.9.2, DPanel has an arbitrary file deletion vu... |
| CVE-2025-67246 | HIGH | 7.3 | 0.2% | Jan 15, 2026 | A local information disclosure vulnerability exists in the Ludashi driver before 5.1025 due to a lack of access control ... |
| CVE-2025-67077 | HIGH | 8.8 | 0.4% | Jan 15, 2026 | File upload vulnerability in Omnispace Agora Project before 25.10 allowing authenticated, or under certain conditions al... |
| CVE-2025-67076 | HIGH | 7.5 | 0.8% | Jan 15, 2026 | Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read fil... |
| CVE-2025-64516 | HIGH | 7.5 | 0.3% | Jan 15, 2026 | GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GL... |
| CVE-2025-61973 | HIGH | 8.8 | 0.1% | Jan 15, 2026 | A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A... |
| CVE-2025-71019 | HIGH | 7.5 | 0.3% | Jan 15, 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the wanSpeed parameter of the sub_65B5C function. T... |
| CVE-2025-70744 | HIGH | 7.5 | 0.3% | Jan 15, 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the cloneType parameter of the sub_65B5C function. ... |
| CVE-2025-13062 | HIGH | 8.8 | 0.5% | Jan 15, 2026 | The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and includin... |
| CVE-2025-14457 | HIGH | 7.4 | 0.2% | Jan 15, 2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modificatio... |
| CVE-2025-13455 | HIGH | 7.8 | 0.1% | Jan 14, 2026 | A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass T... |
| CVE-2025-12166 | HIGH | 7.5 | 0.3% | Jan 14, 2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to bli... |
| CVE-2025-33206 | HIGH | 7.8 | 0.9% | Jan 14, 2026 | NVIDIA NSIGHT Graphics for Linux contains a vulnerability where an attacker could cause command injection. A successful ... |
| CVE-2025-71021 | HIGH | 7.5 | 0.4% | Jan 14, 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the serverName parameter of the sub_65A28 function.... |
| CVE-2025-70747 | HIGH | 7.5 | 0.5% | Jan 14, 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the serviceName parameter of the sub_65A28 function... |
| CVE-2025-37183 | HIGH | 7.2 | 0.4% | Jan 14, 2026 | Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re... |
| CVE-2025-37182 | HIGH | 7.2 | 0.4% | Jan 14, 2026 | Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re... |
| CVE-2025-37181 | HIGH | 7.2 | 0.4% | Jan 14, 2026 | Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re... |
| CVE-2025-9142 | HIGH | 7.5 | 0.1% | Jan 14, 2026 | A local user can trigger Harmony SASE Windows client to write or delete files outside the intended certificate working d... |
| CVE-2025-71143 | HIGH | 7.8 | 0.1% | Jan 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: clk: samsung: exynos-clkout: Assign .num before acc... |
| CVE-2025-71137 | HIGH | 7.8 | 0.2% | Jan 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: fix "UBSAN: shift-out-of-bounds error... |
| CVE-2025-71136 | HIGH | 7.1 | 0.1% | Jan 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: media: adv7842: Avoid possible out-of-bounds array ... |
| CVE-2025-71133 | HIGH | 7.1 | 0.2% | Jan 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: avoid invalid read in irdma_net_event ... |
| CVE-2025-71123 | HIGH | 7.8 | 0.2% | Jan 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix string copying in parse_apply_sb_mount_op... |
| CVE-2025-71122 | HIGH | 7.8 | 0.2% | Jan 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommufd/selftest: Check for overflow in IOMMU_TEST_... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now