2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68966 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect... |
| CVE-2025-68965 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect... |
| CVE-2025-68964 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | Data verification vulnerability in the HiView module. Impact: Successful exploitation of this vulnerability may affect a... |
| CVE-2025-68963 | MEDIUM | 5.3 | 0.1% | Jan 14, 2026 | Man-in-the-middle attack vulnerability in the Clone module. Impact: Successful exploitation of this vulnerability may af... |
| CVE-2025-68962 | MEDIUM | 4.7 | 0.1% | Jan 14, 2026 | Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulner... |
| CVE-2025-68961 | MEDIUM | 4.7 | 0.1% | Jan 14, 2026 | Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulner... |
| CVE-2025-68960 | MEDIUM | 4.7 | 0.1% | Jan 14, 2026 | Multi-thread race condition vulnerability in the video framework module. Impact: Successful exploitation of this vulnera... |
| CVE-2025-68959 | MEDIUM | 5.5 | 0.1% | Jan 14, 2026 | Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulner... |
| CVE-2025-68958 | MEDIUM | 4.7 | 0.1% | Jan 14, 2026 | Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerab... |
| CVE-2025-68957 | MEDIUM | 4.7 | 0.1% | Jan 14, 2026 | Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerab... |
| CVE-2025-68956 | MEDIUM | 4.7 | 0.1% | Jan 14, 2026 | Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerab... |
| CVE-2025-68955 | MEDIUM | 4.7 | 0.1% | Jan 14, 2026 | Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnera... |
| CVE-2025-68947 | MEDIUM | 5.7 | 0.1% | Jan 13, 2026 | NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by othe... |
| CVE-2025-68658 | MEDIUM | 4.8 | 0.2% | Jan 13, 2026 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram... |
| CVE-2025-15056 | MEDIUM | 6.1 | 0.2% | Jan 13, 2026 | A lack of data validation vulnerability in the HTML export feature in Quill in allows Cross-Site Scripting (XSS). This ... |
| CVE-2025-68925 | MEDIUM | 5.3 | 0.1% | Jan 13, 2026 | Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the code doesn't val... |
| CVE-2025-37179 | MEDIUM | 5.3 | 0.3% | Jan 13, 2026 | Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data ... |
| CVE-2025-37177 | MEDIUM | 6.5 | 0.3% | Jan 13, 2026 | An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors runnin... |
| CVE-2025-68949 | MEDIUM | 5.3 | 0.3% | Jan 13, 2026 | n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validat... |
| CVE-2025-8090 | MEDIUM | 6.2 | 0.1% | Jan 13, 2026 | Null pointer dereference in the MsgRegisterEvent() system call could allow an attacker with local access and code execut... |
| CVE-2025-65784 | MEDIUM | 6.5 | 0.3% | Jan 13, 2026 | Insecure permissions in Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows authenticated attackers with low-leve... |
| CVE-2025-62182 | MEDIUM | 5.3 | 0.2% | Jan 13, 2026 | Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, ... |
| CVE-2025-58693 | MEDIUM | 6.5 | 0.6% | Jan 13, 2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7... |
| CVE-2025-46684 | MEDIUM | 5.5 | 0.1% | Jan 13, 2026 | Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissio... |
| CVE-2025-71098 | MEDIUM | 5.5 | 0.1% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: ip6_gre: make ip6gre_header() robust Over the year... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now