2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20762 | MEDIUM | 6.5 | 0.3% | Jan 6, 2026 | In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,... |
| CVE-2025-20761 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,... |
| CVE-2025-20760 | MEDIUM | 6.5 | 0.3% | Jan 6, 2026 | In Modem, there is a possible read of uninitialized heap data due to an uncaught exception. This could lead to remote de... |
| CVE-2025-69197 | MEDIUM | 6.5 | 0.3% | Jan 6, 2026 | Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multip... |
| CVE-2025-68954 | MEDIUM | 5.4 | 0.2% | Jan 6, 2026 | Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP co... |
| CVE-2025-69230 | MEDIUM | 5.3 | 0.3% | Jan 6, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading mu... |
| CVE-2025-69229 | MEDIUM | 5.3 | 0.3% | Jan 6, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling o... |
| CVE-2025-69225 | MEDIUM | 5.3 | 0.2% | Jan 6, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser... |
| CVE-2025-69226 | MEDIUM | 5.3 | 0.3% | Jan 5, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an atta... |
| CVE-2025-69224 | MEDIUM | 6.5 | 0.2% | Jan 5, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python ... |
| CVE-2025-68437 | MEDIUM | 6.8 | 0.4% | Jan 5, 2026 | Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16... |
| CVE-2025-68436 | MEDIUM | 6.5 | 0.2% | Jan 5, 2026 | Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16... |
| CVE-2025-67732 | MEDIUM | 6.5 | 0.3% | Jan 5, 2026 | Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the... |
| CVE-2025-66648 | MEDIUM | 6.1 | 0.2% | Jan 5, 2026 | vega-functions provides function implementations for the Vega expression language. Prior to version 6.1.1, for sites tha... |
| CVE-2025-61916 | MEDIUM | 6.6 | 0.2% | Jan 5, 2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.... |
| CVE-2025-64422 | MEDIUM | 4.3 | 0.3% | Jan 5, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting... |
| CVE-2025-67427 | MEDIUM | 6.5 | 0.2% | Jan 5, 2026 | A Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to... |
| CVE-2025-52517 | MEDIUM | 5.9 | 0.1% | Jan 5, 2026 | An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, ... |
| CVE-2025-52516 | MEDIUM | 6.2 | 0.1% | Jan 5, 2026 | An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, ... |
| CVE-2025-52515 | MEDIUM | 5.1 | 0.1% | Jan 5, 2026 | An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, ... |
| CVE-2025-65922 | MEDIUM | 4.3 | 0.1% | Jan 5, 2026 | PLANKA 2.0.0 lacks X-Frame-Options and CSP frame-ancestors headers, allowing the application to be embedded within malic... |
| CVE-2025-59955 | MEDIUM | 5.7 | 0.3% | Jan 5, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions pri... |
| CVE-2025-67316 | MEDIUM | 5.4 | 0.3% | Jan 5, 2026 | An issue in realme Internet browser v.45.13.4.1 allows a remote attacker to execute arbitrary code via a crafted webpage... |
| CVE-2025-53344 | MEDIUM | 4.3 | 0.1% | Jan 5, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThimPress Thim Core allows Cross Site Request Forgery.This issue affe... |
| CVE-2025-39561 | MEDIUM | 6.5 | 0.2% | Jan 5, 2026 | Missing Authorization vulnerability in Marketing Fire, LLC LoginWP - Pro allows Accessing Functionality Not Properly Con... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now