2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68764 | HIGH | 7.8 | 0.2% | Jan 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFS: Automounted filesystems should inherit ro,noex... |
| CVE-2025-68761 | HIGH | 7.8 | 0.1% | Jan 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: hfs: fix potential use after free in hfs_correct_ne... |
| CVE-2025-68753 | HIGH | 7.1 | 0.2% | Jan 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-motu: add bounds check in put_user l... |
| CVE-2025-5965 | HIGH | 7.2 | 24.8% | Jan 5, 2026 | In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup. Imp... |
| CVE-2025-66518 | HIGH | 8.8 | 0.9% | Jan 5, 2026 | Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.ses... |
| CVE-2025-15240 | HIGH | 8.8 | 0.4% | Jan 5, 2026 | QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing aut... |
| CVE-2025-15239 | HIGH | 7.1 | 0.3% | Jan 5, 2026 | QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticate... |
| CVE-2025-15238 | HIGH | 7.1 | 0.3% | Jan 5, 2026 | QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticate... |
| CVE-2025-15235 | HIGH | 7.1 | 0.3% | Jan 5, 2026 | QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Missing Authorization vulnerability, allowing auth... |
| CVE-2025-15462 | HIGH | 8.8 | 0.9% | Jan 5, 2026 | A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/C... |
| CVE-2025-15461 | HIGH | 8.8 | 0.8% | Jan 5, 2026 | A flaw has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/fo... |
| CVE-2025-15460 | HIGH | 8.8 | 0.6% | Jan 5, 2026 | A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formPptpC... |
| CVE-2025-15459 | HIGH | 8.8 | 0.8% | Jan 5, 2026 | A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of... |
| CVE-2025-14124 | HIGH | 8.6 | 1.6% | Jan 5, 2026 | The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL stat... |
| CVE-2025-15456 | HIGH | 7.5 | 0.4% | Jan 5, 2026 | A vulnerability has been found in bg5sbk MiniCMS up to 1.8. The affected element is an unknown function of the file /mc-... |
| CVE-2025-15443 | HIGH | 7.2 | 0.3% | Jan 4, 2026 | A vulnerability was identified in CRMEB up to 5.6.1. This issue affects some unknown processing of the file /adminapi/pr... |
| CVE-2025-15442 | HIGH | 7.2 | 0.3% | Jan 4, 2026 | A vulnerability was determined in CRMEB up to 5.6.1. This vulnerability affects unknown code of the file /adminapi/expor... |
| CVE-2025-3660 | HIGH | 8.2 | 0.2% | Jan 4, 2026 | Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken access control vulnerability that allows auth... |
| CVE-2025-3646 | HIGH | 8.2 | 0.2% | Jan 4, 2026 | Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authorization bypass vulnerability that allows unau... |
| CVE-2025-64124 | HIGH | 8.8 | 0.9% | Jan 3, 2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Ene... |
| CVE-2025-64120 | HIGH | 8.8 | 0.9% | Jan 2, 2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Ene... |
| CVE-2025-69415 | HIGH | 7.1 | 0.3% | Jan 2, 2026 | In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly a... |
| CVE-2025-69414 | HIGH | 7.1 | 0.2% | Jan 2, 2026 | Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call wit... |
| CVE-2025-67160 | HIGH | 7.5 | 0.9% | Jan 2, 2026 | An issue in Vatilon v1.12.37-20240124 allows attackers to access sensitive directories and files via a directory travers... |
| CVE-2025-67159 | HIGH | 7.5 | 0.3% | Jan 2, 2026 | Vatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now