2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66620 | HIGH | 7.2 | 0.4% | Jan 7, 2026 | An unused webshell in MicroServer allows unlimited login attempts, with sudo rights on certain files and directories. An... |
| CVE-2025-64305 | HIGH | 7.1 | 0.1% | Jan 7, 2026 | MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vend... |
| CVE-2025-66560 | HIGH | 7.5 | 0.3% | Jan 7, 2026 | Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. Prior to versions 3.31.0, 3.... |
| CVE-2025-4677 | HIGH | 7.1 | 0.2% | Jan 7, 2026 | Insufficient Session Expiration vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.Thi... |
| CVE-2025-67366 | HIGH | 7.5 | 0.5% | Jan 7, 2026 | @sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of fil... |
| CVE-2025-67364 | HIGH | 7.5 | 0.6% | Jan 7, 2026 | fast-filesystem-mcp version 3.4.0 contains a critical path traversal vulnerability in its file operation tools including... |
| CVE-2025-66786 | HIGH | 7.5 | 0.3% | Jan 7, 2026 | OpenAirInterface CN5G AMF<=v2.0.1 There is a logical error when processing JSON format requests. Unauthorized remote att... |
| CVE-2025-65805 | HIGH | 7.5 | 0.3% | Jan 7, 2026 | OpenAirInterface CN5G AMF<=v2.1.9 has a buffer overflow vulnerability in processing NAS messages. Unauthorized remote at... |
| CVE-2025-4676 | HIGH | 8.8 | 0.2% | Jan 7, 2026 | Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP C... |
| CVE-2025-4675 | HIGH | 7.1 | 0.2% | Jan 7, 2026 | Improper Check for Unusual or Exceptional Conditions vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP C... |
| CVE-2025-46494 | HIGH | 7.1 | 0.1% | Jan 7, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesgrove Widget... |
| CVE-2025-9611 | HIGH | 7.2 | 1.1% | Jan 7, 2026 | Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on incoming connections. Th... |
| CVE-2025-69082 | HIGH | 7.1 | 0.1% | Jan 7, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Frenify Arlo arlo ... |
| CVE-2025-69081 | HIGH | 8.1 | 0.4% | Jan 7, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-69080 | HIGH | 8.1 | 0.4% | Jan 7, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47396 | HIGH | 7.8 | 0.1% | Jan 7, 2026 | Memory corruption occurs when a secure application is launched on a device with insufficient memory. |
| CVE-2025-47394 | HIGH | 7.8 | 0.1% | Jan 7, 2026 | Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations. |
| CVE-2025-47393 | HIGH | 7.8 | 0.1% | Jan 7, 2026 | Memory corruption when accessing resources in kernel driver. |
| CVE-2025-47388 | HIGH | 7.8 | 0.1% | Jan 7, 2026 | Memory corruption while passing pages to DSP with an unaligned starting address. |
| CVE-2025-47380 | HIGH | 7.8 | 0.1% | Jan 7, 2026 | Memory corruption while preprocessing IOCTLs in sensors. |
| CVE-2025-47356 | HIGH | 7.8 | 0.1% | Jan 7, 2026 | Memory Corruption when multiple threads concurrently access and modify shared resources. |
| CVE-2025-47348 | HIGH | 7.8 | 0.1% | Jan 7, 2026 | Memory corruption while processing identity credential operations in the trusted application. |
| CVE-2025-47346 | HIGH | 7.8 | 0.1% | Jan 7, 2026 | Memory corruption while processing a secure logging command in the trusted application. |
| CVE-2025-47345 | HIGH | 8.4 | 0.1% | Jan 7, 2026 | Cryptographic issue may occur while encrypting license data. |
| CVE-2025-47343 | HIGH | 7.8 | 0.1% | Jan 7, 2026 | Memory corruption while processing a video session to set video parameters. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now