2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12812 | MEDIUM | 5.3 | 0.3% | Feb 18, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Delinea Inc. Cloud Suite and Pri... |
| CVE-2025-12811 | MEDIUM | 6.9 | 0.3% | Feb 18, 2026 | Improper Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Delinea Inc. Cloud Suite and Privile... |
| CVE-2025-8860 | LOW | 3.3 | 0.1% | Feb 18, 2026 | A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, t... |
| CVE-2025-1272 | HIGH | 7.7 | 0.2% | Feb 18, 2026 | The Linux Kernel lockdown mode for kernel versions starting on 6.12 and above for Fedora Linux has the lockdown mode dis... |
| CVE-2025-14876 | MEDIUM | 5.5 | 0.1% | Feb 18, 2026 | A flaw was found in the virtio-crypto device of QEMU. A malicious guest operating system can exploit a missing length li... |
| CVE-2025-12343 | MEDIUM | 5.5 | 0.1% | Feb 18, 2026 | A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in... |
| CVE-2025-10256 | MEDIUM | 5.5 | 0.3% | Feb 18, 2026 | A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a... |
| CVE-2025-0577 | MEDIUM | 4.8 | 0.2% | Feb 18, 2026 | An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return pr... |
| CVE-2025-70064 | HIGH | 8.8 | 0.5% | Feb 18, 2026 | PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient... |
| CVE-2025-70063 | MEDIUM | 6.5 | 0.3% | Feb 18, 2026 | The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference ... |
| CVE-2025-70062 | MEDIUM | 6.5 | 0.2% | Feb 18, 2026 | PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor... |
| CVE-2025-69287 | MEDIUM | 5.4 | 0.3% | Feb 18, 2026 | The BSV Blockchain SDK is a unified TypeScript SDK for developing scalable apps on the BSV Blockchain. Prior to version ... |
| CVE-2025-70152 | CRITICAL | 9.8 | 0.4% | Feb 18, 2026 | code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management... |
| CVE-2025-70151 | HIGH | 8.8 | 0.6% | Feb 18, 2026 | code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestr... |
| CVE-2025-70150 | CRITICAL | 9.8 | 0.6% | Feb 18, 2026 | CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that al... |
| CVE-2025-70148 | HIGH | 7.5 | 0.4% | Feb 18, 2026 | Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allo... |
| CVE-2025-14009 | CRITICAL | 10 | 0.8% | Feb 18, 2026 | A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter f... |
| CVE-2025-70149 | CRITICAL | 9.8 | 0.4% | Feb 18, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parame... |
| CVE-2025-70147 | HIGH | 7.5 | 0.4% | Feb 18, 2026 | Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 all... |
| CVE-2025-70146 | CRITICAL | 9.1 | 0.5% | Feb 18, 2026 | Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Genera... |
| CVE-2025-70141 | CRITICAL | 9.4 | 0.5% | Feb 18, 2026 | SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX disp... |
| CVE-2025-13965 | — | — | — | Feb 18, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-12500. Reason: This candidate is a ... |
| CVE-2025-13933 | — | — | — | Feb 18, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-12500. Reason: This candidate is a ... |
| CVE-2025-13602 | — | — | — | Feb 18, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2025-71237 | MEDIUM | 5.5 | 0.1% | Feb 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: nilfs2: Fix potential block overflow that cause sys... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now