2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15578 | CRITICAL | 9.8 | 0.3% | Feb 16, 2026 | Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the sys... |
| CVE-2025-65717 | MEDIUM | 4.3 | 0.5% | Feb 16, 2026 | An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction w... |
| CVE-2025-65716 | HIGH | 8.8 | 0.6% | Feb 16, 2026 | An issue in Visual Studio Code Extensions Markdown Preview Enhanced v0.8.18 allows attackers to execute arbitrary code v... |
| CVE-2025-65715 | HIGH | 7.8 | 0.3% | Feb 16, 2026 | An issue in the code-runner.executorMap setting of Visual Studio Code Extensions Code Runner v0.12.2 allows attackers to... |
| CVE-2025-14573 | LOW | 2.7 | 0.2% | Feb 16, 2026 | Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team... |
| CVE-2025-14350 | MEDIUM | 4.3 | 0.2% | Feb 16, 2026 | Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate team membership whe... |
| CVE-2025-2418 | MEDIUM | 4.3 | 0.2% | Feb 16, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in TR7 Cyber Defense Inc. Web Application Firewall a... |
| CVE-2025-13821 | MEDIUM | 5.7 | 0.2% | Feb 16, 2026 | Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket ... |
| CVE-2025-59905 | MEDIUM | 6.1 | 0.1% | Feb 16, 2026 | Cross-Site Scripting (XSS) vulnerability reflected in Kubysoft, which occurs through multiple parameters within the endp... |
| CVE-2025-59904 | MEDIUM | 5.4 | 0.1% | Feb 16, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, which is triggered through multiple parameters in the '/kFo... |
| CVE-2025-59903 | MEDIUM | 5.4 | 0.1% | Feb 16, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, where uploaded SVG images are not properly sanitized. This ... |
| CVE-2025-32063 | MEDIUM | 6.8 | 0.2% | Feb 15, 2026 | There is a misconfiguration vulnerability inside the Infotainment ECU manufactured by BOSCH. The vulnerability happens d... |
| CVE-2025-32062 | HIGH | 8.8 | 0.4% | Feb 15, 2026 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bos... |
| CVE-2025-32061 | HIGH | 8.8 | 0.4% | Feb 15, 2026 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bos... |
| CVE-2025-32060 | MEDIUM | 6.7 | 0.1% | Feb 15, 2026 | The system suffers from the absence of a kernel module signature verification. If an attacker can execute commands on be... |
| CVE-2025-32059 | HIGH | 8.8 | 0.4% | Feb 15, 2026 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bos... |
| CVE-2025-32058 | CRITICAL | 9.3 | 0.2% | Feb 15, 2026 | The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment... |
| CVE-2025-71224 | — | — | 0.2% | Feb 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: ocb: skip rx_no_sta when interface ... |
| CVE-2025-71223 | MEDIUM | 5.5 | 0.1% | Feb 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb/server: fix refcount leak in smb2_open() When ... |
| CVE-2025-71222 | MEDIUM | 5.5 | 0.1% | Feb 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: ensure skb headroom before skb_push ... |
| CVE-2025-71221 | HIGH | 7 | 0.1% | Feb 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: mmp_pdma: Fix race condition in mmp_pdma... |
| CVE-2025-71220 | HIGH | 7.8 | 0.1% | Feb 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb/server: call ksmbd_session_rpc_close() on error... |
| CVE-2025-71204 | MEDIUM | 5.5 | 0.1% | Feb 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb/server: fix refcount leak in parse_durable_hand... |
| CVE-2025-71203 | HIGH | 7 | 0.1% | Feb 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: riscv: Sanitize syscall table indexing under specul... |
| CVE-2025-71202 | MEDIUM | 5.5 | 0.1% | Feb 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommu/sva: invalidate stale IOTLB entries for kerne... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now