Live disclosure tracker · updated continuously

2025 Data Breaches

2025 marked a continued acceleration in confirmed-breach disclosures. Below is every 2025 incident LeakTrace has indexed.

98B+
Records Exposed
637
Incidents
94+
Countries
+104%
Breach Velocity YoY
Browse by sector
All breaches Healthcare Finance Government Technology Retail Education Legal
Browse by year
2024 2025 2026

2025 Data Breaches (637 indexed)

high · government · Dec 26, 2025

Utair

401,400 records exposed — Dates of birth, Email addresses, Genders, Loyalty program details and 4 more

View incident → Original disclosure Indexed 3 months, 2 weeks ago
high · tech · Dec 22, 2025

Digiever DS-2105 Pro

Digiever DS-2105 Pro Missing Authorization Vulnerability — Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for command injection via time_tzsetup.cgi.

View incident → Original disclosure Indexed 3 months, 2 weeks ago
high · tech · Dec 19, 2025

WatchGuard Firebox

WatchGuard Firebox Out of Bounds Write Vulnerability — WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attac

View incident → Original disclosure Indexed 3 months, 3 weeks ago
high · tech · Dec 17, 2025

Cisco Multiple Products

Cisco Multiple Products Improper Input Validation Vulnerability — Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows thr

View incident → Original disclosure Indexed 3 months, 3 weeks ago
high · tech · Dec 17, 2025

ASUS Live Update

ASUS Live Update Embedded Malicious Code Vulnerability — ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modifications introduced through a supply chain compro

View incident → Original disclosure Indexed 3 months, 3 weeks ago
high · tech · Dec 17, 2025

SonicWall SMA1000 appliance

SonicWall SMA1000 Missing Authorization Vulnerability — SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices.

View incident → Original disclosure Indexed 3 months, 3 weeks ago
high · tech · Dec 16, 2025

Fortinet Multiple Products

Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability — Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulner

View incident → Original disclosure Indexed 3 months, 3 weeks ago
high · tech · Dec 15, 2025

Apple Multiple Products

Apple Multiple Products Use-After-Free WebKit Vulnerability — Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to me

View incident → Original disclosure Indexed 3 months, 3 weeks ago
high · tech · Dec 15, 2025

Gladinet CentreStack and Triofox

Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability — Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulne

View incident → Original disclosure Indexed 3 months, 3 weeks ago
high · tech · Dec 12, 2025

Sierra Wireless AirLink ALEOS

Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability — Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted H

View incident → Original disclosure Indexed 3 months, 4 weeks ago
high · tech · Dec 12, 2025

Google Chromium

Google Chromium Out of Bounds Memory Access Vulnerability — Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a c

View incident → Original disclosure Indexed 3 months, 4 weeks ago
high · tech · Dec 11, 2025

OSGeo GeoServer

OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability — OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accep

high · tech · Dec 9, 2025

RARLAB WinRAR

RARLAB WinRAR Path Traversal Vulnerability — RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user.

high · tech · Dec 9, 2025

Microsoft Windows

Microsoft Windows Use After Free Vulnerability — Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally.