2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71166 | MEDIUM | 5.4 | 0.2% | Jan 14, 2026 | Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the admi... |
| CVE-2025-71165 | MEDIUM | 5.4 | 0.2% | Jan 14, 2026 | Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the admi... |
| CVE-2025-71164 | MEDIUM | 5.4 | 0.2% | Jan 14, 2026 | Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the Edit... |
| CVE-2025-14557 | MEDIUM | 4.8 | 0.2% | Jan 14, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Face... |
| CVE-2025-14556 | MEDIUM | 5.4 | 0.2% | Jan 14, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Flag... |
| CVE-2025-11224 | MEDIUM | 5.4 | 0.3% | Jan 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.3.6, 18.4 before 18.4.4, and ... |
| CVE-2025-65397 | MEDIUM | 6.8 | 0.3% | Jan 14, 2026 | An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 ... |
| CVE-2025-63644 | MEDIUM | 5.4 | 0.3% | Jan 14, 2026 | A stored cross-site scripting (XSS) vulnerability exists in pH7Software pH7-Social-Dating-CMS 17.9.1 in the user profile... |
| CVE-2025-67835 | MEDIUM | 6.5 | 0.3% | Jan 14, 2026 | Paessler PRTG Network Monitor before 25.4.114 allows Denial-of-Service (DoS) by an authenticated attacker via the Notifi... |
| CVE-2025-67834 | MEDIUM | 5.4 | 0.2% | Jan 14, 2026 | Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the filter parameter. |
| CVE-2025-67833 | MEDIUM | 6.1 | 0.2% | Jan 14, 2026 | Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the tag parameter. |
| CVE-2025-65396 | MEDIUM | 6.1 | 0.2% | Jan 14, 2026 | A vulnerability in the boot process of Blurams Flare Camera version 24.1114.151.929 and earlier allows a physically prox... |
| CVE-2025-37185 | MEDIUM | 4.8 | 0.2% | Jan 14, 2026 | Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re... |
| CVE-2025-67399 | MEDIUM | 4.6 | 0.2% | Jan 14, 2026 | An issue in AIRTH SMART HOME AQI MONITOR Bootloader v.1.005 allows a physically proximate attacker to obtain sensitive i... |
| CVE-2025-14242 | MEDIUM | 6.5 | 0.7% | Jan 14, 2026 | A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls comman... |
| CVE-2025-71144 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: mptcp: ensure context reset on disconnect() After ... |
| CVE-2025-71142 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: cpuset: fix warning when disabling remote partition... |
| CVE-2025-71141 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/tilcdc: Fix removal actions in case of failed p... |
| CVE-2025-71139 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: kernel/kexec: fix IMA when allocation happens in CM... |
| CVE-2025-71138 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: Add missing NULL pointer check for pin... |
| CVE-2025-71135 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: md/raid5: fix possible null-pointer dereferences in... |
| CVE-2025-71134 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: change all pageblocks migrate type o... |
| CVE-2025-71132 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: smc91x: fix broken irq-context in PREEMPT_RT When ... |
| CVE-2025-71131 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: seqiv - Do not use req->iv after crypto_aea... |
| CVE-2025-71130 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Zero-initialize the eb.vma array in i... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now