2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66049 | HIGH | 7.5 | 0.4% | Jan 9, 2026 | Vivotek IP7137 camera with firmware version 0200a is vulnerable to an information disclosure issue where live camera foo... |
| CVE-2025-64092 | HIGH | 7.5 | 0.4% | Jan 9, 2026 | This vulnerability allows unauthenticated attackers to inject an SQL request into GET request parameters and directly qu... |
| CVE-2025-64091 | HIGH | 8.8 | 0.3% | Jan 9, 2026 | This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device. |
| CVE-2025-64090 | HIGH | 8.8 | 0.4% | Jan 9, 2026 | This vulnerability allows authenticated attackers to execute commands via the hostname of the device. |
| CVE-2025-69195 | HIGH | 8.8 | 0.3% | Jan 9, 2026 | A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization lo... |
| CVE-2025-14937 | HIGH | 7.2 | 0.3% | Jan 9, 2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acff' parame... |
| CVE-2025-14657 | HIGH | 7.2 | 0.3% | Jan 9, 2026 | The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unau... |
| CVE-2025-15057 | HIGH | 7.2 | 0.2% | Jan 9, 2026 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fh` (fingerprint) para... |
| CVE-2025-15055 | HIGH | 7.2 | 0.2% | Jan 9, 2026 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' and 'resource' ... |
| CVE-2025-66315 | HIGH | 8.8 | 0.2% | Jan 9, 2026 | There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper director... |
| CVE-2025-14436 | HIGH | 7.2 | 0.3% | Jan 8, 2026 | The Brevo for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_connection_id’... |
| CVE-2025-68719 | HIGH | 8.8 | 0.4% | Jan 8, 2026 | KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 mishandle configuration management. Once any user is logged in and main... |
| CVE-2025-68716 | HIGH | 8.4 | 0.2% | Jan 8, 2026 | KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The roo... |
| CVE-2025-15464 | HIGH | 7.5 | 0.5% | Jan 8, 2026 | Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, ... |
| CVE-2025-65518 | HIGH | 7.5 | 0.5% | Jan 8, 2026 | Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability e... |
| CVE-2025-68158 | HIGH | 8.8 | 0.2% | Jan 8, 2026 | Authlib is a Python library which builds OAuth and OpenID Connect servers. In versions 1.0.0 through 1.6.5, cache-backed... |
| CVE-2025-56424 | HIGH | 7.5 | 0.5% | Jan 8, 2026 | An issue in Insiders Technologies GmbH e-invoice pro before release 1 Service Pack 2 allows a remote attacker to cause a... |
| CVE-2025-50334 | HIGH | 7.5 | 1.0% | Jan 8, 2026 | An issue in Technitium DNS Server v.13.5 allows a remote attacker to cause a denial of service via the rate-limiting com... |
| CVE-2025-68151 | HIGH | 7.5 | 0.4% | Jan 8, 2026 | CoreDNS is a DNS server that chains plugins. Prior to version 1.14.0, multiple CoreDNS server implementations (gRPC, HTT... |
| CVE-2025-67858 | HIGH | 7 | 0.2% | Jan 8, 2026 | A Improper Neutralization of Argument Delimiters vulnerability in Foomuuri can lead to integrity loss of the firewall co... |
| CVE-2025-67089 | HIGH | 8.1 | 1.4% | Jan 8, 2026 | A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present ... |
| CVE-2025-63611 | HIGH | 8.7 | 0.3% | Jan 8, 2026 | Cross-Site Scripting in phpgurukul Hostel Management System v2.1 user-provided complaint fields (Explain the Complaint) ... |
| CVE-2025-66003 | HIGH | 7.3 | 0.1% | Jan 8, 2026 | An External Control of File Name or Path vulnerability in smb4k allowsl ocal users to perform a local root exploit via s... |
| CVE-2025-14025 | HIGH | 8.5 | 0.4% | Jan 8, 2026 | A flaw was found in Ansible Automation Platform (AAP). Read-only scoped OAuth2 API Tokens in AAP, are enforced at the Ga... |
| CVE-2025-69260 | HIGH | 7.5 | 1.4% | Jan 8, 2026 | A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now