2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41077 | HIGH | 8.1 | 0.2% | Jan 12, 2026 | IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the... |
| CVE-2025-41005 | HIGH | 8.7 | 0.3% | Jan 12, 2026 | Imaster's MEMS Events CRM contains an SQL injection vulnerability in‘keyword’ parameter in ‘/memsdemo/exchange_offers.ph... |
| CVE-2025-41004 | HIGH | 8.7 | 0.3% | Jan 12, 2026 | Imaster's Patient Records Management System is vulnerable to SQL Injection in the endpoint ‘/projects/hospital/admin/com... |
| CVE-2025-14279 | HIGH | 8.1 | 0.2% | Jan 12, 2026 | MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header validat... |
| CVE-2025-69276 | HIGH | 8.8 | 0.3% | Jan 12, 2026 | Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Object Injection... |
| CVE-2025-69274 | HIGH | 8.8 | 0.2% | Jan 12, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows P... |
| CVE-2025-69273 | HIGH | 7.5 | 0.3% | Jan 12, 2026 | Improper Authentication vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Authentication Bypass.This... |
| CVE-2025-69272 | HIGH | 7.5 | 0.1% | Jan 12, 2026 | Cleartext Transmission of Sensitive Information vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sn... |
| CVE-2025-69271 | HIGH | 7.5 | 0.2% | Jan 12, 2026 | Insufficiently Protected Credentials vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Atta... |
| CVE-2025-68493 | HIGH | 8.1 | 23.1% | Jan 11, 2026 | Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 befo... |
| CVE-2025-62235 | HIGH | 8.1 | 0.4% | Jan 10, 2026 | Authentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could le... |
| CVE-2025-53477 | HIGH | 7.5 | 0.7% | Jan 10, 2026 | NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command T... |
| CVE-2025-52435 | HIGH | 7.5 | 0.2% | Jan 10, 2026 | J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause ... |
| CVE-2025-13457 | HIGH | 7.5 | 0.3% | Jan 10, 2026 | The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and... |
| CVE-2025-59057 | HIGH | 7.6 | 0.4% | Jan 10, 2026 | React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 ... |
| CVE-2025-67070 | HIGH | 8.2 | 0.3% | Jan 9, 2026 | A vulnerability exists in Intelbras CFTV IP NVD 9032 R Ftd V2.800.00IB00C.0.T, which allows an unauthenticated attacker ... |
| CVE-2025-66744 | HIGH | 7.5 | 1.4% | Jan 9, 2026 | In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to... |
| CVE-2025-46645 | HIGH | 7.2 | 1.4% | Jan 9, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.... |
| CVE-2025-15495 | HIGH | 7.2 | 0.4% | Jan 9, 2026 | A vulnerability was found in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/editsite... |
| CVE-2025-15494 | HIGH | 8.8 | 0.4% | Jan 9, 2026 | A vulnerability has been found in RainyGao DocSys up to 2.02.37. This affects an unknown function of the file com/DocSys... |
| CVE-2025-15035 | HIGH | 7.3 | 0.3% | Jan 9, 2026 | Improper Input Validation vulnerability in TP-Link Archer AXE75 v1.6 (vpn modules) allows an authenticated adjacent atta... |
| CVE-2025-67133 | HIGH | 7.5 | 0.5% | Jan 9, 2026 | An issue in Hero Motocorp Vida V1 Pro 2.0.7 allows a local attacker to cause a denial of service via the BLE component |
| CVE-2025-56225 | HIGH | 7.5 | 0.4% | Jan 9, 2026 | fluidsynth-2.4.6 and earlier versions is vulnerable to Null pointer dereference in fluid_synth_monopoly.c, that can be t... |
| CVE-2025-15492 | HIGH | 8.8 | 0.4% | Jan 9, 2026 | A vulnerability was detected in RainyGao DocSys up to 2.02.36. The affected element is an unknown function of the file s... |
| CVE-2025-66052 | HIGH | 7.2 | 1.3% | Jan 9, 2026 | Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now