2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-33181 | HIGH | 8.8 | 0.4% | Feb 24, 2026 | NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could ... |
| CVE-2025-33180 | HIGH | 8.8 | 0.8% | Feb 24, 2026 | NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could ... |
| CVE-2025-33179 | HIGH | 8.8 | 0.5% | Feb 24, 2026 | NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could ... |
| CVE-2025-1789 | HIGH | 7.8 | 0.1% | Feb 24, 2026 | Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this ... |
| CVE-2025-1787 | MEDIUM | 4.2 | 0.1% | Feb 24, 2026 | Local admin could to leak information from the Genetec Update Service configuration web page. An authenticated, admin pr... |
| CVE-2025-62512 | MEDIUM | 5.3 | 0.8% | Feb 24, 2026 | Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the ... |
| CVE-2025-14963 | HIGH | 7.8 | 0.1% | Feb 24, 2026 | A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the abil... |
| CVE-2025-13776 | HIGH | 7.1 | 0.1% | Feb 24, 2026 | Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A m... |
| CVE-2025-69985 | CRITICAL | 9.8 | 5.6% | Feb 24, 2026 | FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnera... |
| CVE-2025-63409 | HIGH | 8.8 | 0.3% | Feb 24, 2026 | Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to mod... |
| CVE-2025-47904 | MEDIUM | 4.1 | 0.1% | Feb 24, 2026 | Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software ... |
| CVE-2025-67445 | HIGH | 7.5 | 0.4% | Feb 24, 2026 | TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI read... |
| CVE-2025-10010 | MEDIUM | 6.8 | 0.3% | Feb 24, 2026 | The CPSD CryptoPro Secure Disk application boots a small Linux operating system to perform user authentication before us... |
| CVE-2025-14577 | CRITICAL | 9.8 | 0.4% | Feb 24, 2026 | Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to e... |
| CVE-2025-27555 | MEDIUM | 6.5 | 0.4% | Feb 24, 2026 | Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensiti... |
| CVE-2025-11165 | CRITICAL | 9.9 | 0.3% | Feb 24, 2026 | A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users wit... |
| CVE-2025-40541 | HIGH | 7.2 | 0.6% | Feb 24, 2026 | An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor... |
| CVE-2025-40540 | HIGH | 7.2 | 0.4% | Feb 24, 2026 | A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arb... |
| CVE-2025-40539 | HIGH | 7.2 | 0.4% | Feb 24, 2026 | A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arb... |
| CVE-2025-40538 | HIGH | 7.2 | 0.5% | Feb 24, 2026 | A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to crea... |
| CVE-2025-15589 | HIGH | 7.2 | 0.7% | Feb 24, 2026 | A vulnerability was determined in MuYuCMS 2.7. Affected is the function delete_dir_file of the file application/admin/co... |
| CVE-2025-15386 | HIGH | 8.8 | 0.3% | Feb 24, 2026 | The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack du... |
| CVE-2025-13943 | HIGH | 8.8 | 1.4% | Feb 24, 2026 | A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware ... |
| CVE-2025-13942 | CRITICAL | 9.8 | 1.1% | Feb 24, 2026 | A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C... |
| CVE-2025-11848 | MEDIUM | 4.9 | 1.8% | Feb 24, 2026 | A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version throu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now