2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11847 | MEDIUM | 4.9 | 1.7% | Feb 24, 2026 | A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions thro... |
| CVE-2025-11846 | MEDIUM | 4.9 | 1.1% | Feb 24, 2026 | A null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions... |
| CVE-2025-11845 | MEDIUM | 4.9 | 0.8% | Feb 24, 2026 | A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware ve... |
| CVE-2025-9120 | HIGH | 8.6 | 0.2% | Feb 24, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Carbonite Safe Server Backup allows... |
| CVE-2025-69253 | MEDIUM | 5.3 | 0.3% | Feb 24, 2026 | free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of th... |
| CVE-2025-69252 | HIGH | 7.5 | 0.5% | Feb 24, 2026 | free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile co... |
| CVE-2025-69251 | MEDIUM | 5.3 | 0.5% | Feb 24, 2026 | free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile co... |
| CVE-2025-69250 | HIGH | 7.5 | 0.4% | Feb 24, 2026 | free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile co... |
| CVE-2025-69248 | HIGH | 7.5 | 0.6% | Feb 23, 2026 | free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of fr... |
| CVE-2025-69247 | HIGH | 7.5 | 0.5% | Feb 23, 2026 | free5GC go-upf is the User Plane Function (UPF) implementation for 5G networks that is part of the free5GC project. Vers... |
| CVE-2025-69232 | HIGH | 7.5 | 0.4% | Feb 23, 2026 | free5GC is an open-source project for 5th generation (5G) mobile core networks. free5GC go-upf versions up to and includ... |
| CVE-2025-69208 | MEDIUM | 5.3 | 0.3% | Feb 23, 2026 | free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core... |
| CVE-2025-71056 | HIGH | 8.1 | 0.2% | Feb 23, 2026 | Improper session management in GCOM EPON 1GE ONU version C00R371V00B01 allows attackers to execute a session hijacking a... |
| CVE-2025-70328 | HIGH | 8.8 | 1.8% | Feb 23, 2026 | TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of... |
| CVE-2025-70327 | CRITICAL | 9.8 | 0.7% | Feb 23, 2026 | TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of t... |
| CVE-2025-68930 | MEDIUM | 6.5 | 0.5% | Feb 23, 2026 | Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijack... |
| CVE-2025-70329 | HIGH | 8 | 3.2% | Feb 23, 2026 | TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the ... |
| CVE-2025-67733 | HIGH | 7.1 | 0.6% | Feb 23, 2026 | Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use ... |
| CVE-2025-63946 | HIGH | 7.4 | 0.2% | Feb 23, 2026 | A privilege escalation (PE) vulnerability in the Tencent PC Manager app thru 17.10.28554.205 on Windows devices enables ... |
| CVE-2025-63945 | HIGH | 7.4 | 0.2% | Feb 23, 2026 | A privilege escalation (PE) vulnerability in the Tencent iOA app thru 210.9.28693.621001 on Windows devices enables a lo... |
| CVE-2025-61147 | MEDIUM | 6.2 | 0.2% | Feb 23, 2026 | strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::comp... |
| CVE-2025-61146 | MEDIUM | 4 | 0.1% | Feb 23, 2026 | saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c. |
| CVE-2025-61145 | MEDIUM | 5 | 0.1% | Feb 23, 2026 | libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c. |
| CVE-2025-61144 | HIGH | 7.3 | 0.3% | Feb 23, 2026 | libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function. |
| CVE-2025-61143 | MEDIUM | 5.5 | 0.1% | Feb 23, 2026 | libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now