2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47553 | HIGH | 8.8 | 0.3% | Jan 6, 2026 | Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This is... |
| CVE-2025-36589 | HIGH | 7.1 | 0.2% | Jan 6, 2026 | Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vul... |
| CVE-2025-59379 | HIGH | 7.5 | 0.3% | Jan 6, 2026 | DwyerOmega Isensix Advanced Remote Monitoring System (ARMS) 1.5.7 allows an attacker to retrieve sensitive information f... |
| CVE-2025-14979 | HIGH | 7.8 | 0.1% | Jan 6, 2026 | AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privilege... |
| CVE-2025-14026 | HIGH | 7.8 | 0.2% | Jan 6, 2026 | Forcepoint One DLP Client, version 23.04.5642 (and possibly newer versions), includes a restricted version of Python 2.5... |
| CVE-2025-14997 | HIGH | 8.8 | 0.6% | Jan 6, 2026 | The BuddyPress Xprofile Custom Field Types plugin for WordPress is vulnerable to arbitrary file deletion due to insuffic... |
| CVE-2025-12793 | HIGH | 7.8 | 0.1% | Jan 6, 2026 | An uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the ap... |
| CVE-2025-20801 | HIGH | 7 | 0.1% | Jan 6, 2026 | In seninf, there is a possible memory corruption due to a race condition. This could lead to local escalation of privile... |
| CVE-2025-20800 | HIGH | 7.8 | 0.1% | Jan 6, 2026 | In mminfra, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o... |
| CVE-2025-20799 | HIGH | 7.8 | 0.1% | Jan 6, 2026 | In c2ps, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege i... |
| CVE-2025-20798 | HIGH | 7.8 | 0.1% | Jan 6, 2026 | In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o... |
| CVE-2025-20797 | HIGH | 7.8 | 0.1% | Jan 6, 2026 | In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o... |
| CVE-2025-20796 | HIGH | 7.8 | 0.1% | Jan 6, 2026 | In imgsys, there is a possible out of bounds write due to improper input validation. This could lead to local escalation... |
| CVE-2025-20795 | HIGH | 7.8 | 0.1% | Jan 6, 2026 | In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatio... |
| CVE-2025-20781 | HIGH | 7.8 | 0.1% | Jan 6, 2026 | In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg... |
| CVE-2025-20780 | HIGH | 7.8 | 0.1% | Jan 6, 2026 | In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg... |
| CVE-2025-20779 | HIGH | 7 | 0.1% | Jan 6, 2026 | In display, there is a possible use after free due to a race condition. This could lead to local escalation of privilege... |
| CVE-2025-20778 | HIGH | 7.8 | 0.1% | Jan 6, 2026 | In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o... |
| CVE-2025-15364 | HIGH | 7.3 | 0.2% | Jan 6, 2026 | The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up ... |
| CVE-2025-69228 | HIGH | 7.5 | 0.3% | Jan 6, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a reques... |
| CVE-2025-69227 | HIGH | 7.5 | 0.3% | Jan 6, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an i... |
| CVE-2025-69223 | HIGH | 7.5 | 0.5% | Jan 5, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bo... |
| CVE-2025-68953 | HIGH | 7.5 | 0.4% | Jan 5, 2026 | Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests... |
| CVE-2025-68455 | HIGH | 7.2 | 0.8% | Jan 5, 2026 | Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 ar... |
| CVE-2025-68454 | HIGH | 8.8 | 0.8% | Jan 5, 2026 | Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 ar... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now