2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14186 | LOW | 3.5 | 0.2% | Dec 7, 2025 | A security flaw has been discovered in Grandstream GXP1625 1.0.7.4. The impacted element is an unknown function of the f... |
| CVE-2025-66549 | LOW | 2.7 | 0.2% | Dec 5, 2025 | Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside ... |
| CVE-2025-66515 | LOW | 2.7 | 0.3% | Dec 5, 2025 | The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenti... |
| CVE-2025-66546 | LOW | 3.3 | 0.1% | Dec 5, 2025 | Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly ... |
| CVE-2025-66479 | LOW | 1.8 | 0.1% | Dec 4, 2025 | Anthropic Sandbox Runtime is a lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrar... |
| CVE-2025-12997 | LOW | 3.1 | 0.2% | Dec 4, 2025 | Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with... |
| CVE-2025-20388 | LOW | 2.7 | 0.3% | Dec 3, 2025 | In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507... |
| CVE-2025-12954 | LOW | 2.7 | 0.2% | Dec 3, 2025 | The Timetable and Event Schedule by MotoPress WordPress plugin before 2.4.16 does not verify a user has access to a spec... |
| CVE-2025-13640 | LOW | 3.5 | 0.2% | Dec 2, 2025 | Inappropriate implementation in Passwords in Google Chrome prior to 143.0.7499.41 allowed a local attacker to bypass aut... |
| CVE-2025-59700 | LOW | 3.9 | 0.1% | Dec 2, 2025 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker... |
| CVE-2025-59696 | LOW | 3.2 | 0.2% | Dec 2, 2025 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker... |
| CVE-2025-65858 | LOW | 3.5 | 0.2% | Dec 2, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript... |
| CVE-2025-13879 | LOW | 2.7 | 0.5% | Dec 2, 2025 | Directory traversal vulnerability in SOLIDserver IPAM v8.2.3. This vulnerability allows an authenticated user with admin... |
| CVE-2025-58487 | LOW | 3.3 | 0.1% | Dec 2, 2025 | Improper authorization in Samsung Account prior to version 15.5.01.1 allows local attacker to launch arbitrary activity ... |
| CVE-2025-58483 | LOW | 3.3 | 0.1% | Dec 2, 2025 | Improper export of android application components in Galaxy Store for Galaxy Watch prior to version 1.0.06.29 allows loc... |
| CVE-2025-13805 | LOW | 3.7 | 0.3% | Dec 1, 2025 | A weakness has been identified in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This affects the function getInputStream of the ... |
| CVE-2025-13795 | LOW | 2.4 | 0.2% | Nov 30, 2025 | A weakness has been identified in codingWithElias School Management System up to f1ac334bfd89ae9067cc14dea12ec6ff3f078c0... |
| CVE-2025-6666 | LOW | 2 | 0.1% | Nov 29, 2025 | A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125. Affected by this vulnerability is an ... |
| CVE-2025-66372 | LOW | 2.8 | 0.1% | Nov 28, 2025 | Mustang before 2.16.3 allows exfiltrating files via XXE attacks. |
| CVE-2025-58308 | LOW | 3.3 | 0.1% | Nov 28, 2025 | Vulnerability of improper criterion security check in the call module. Impact: Successful exploitation of this vulnerabi... |
| CVE-2025-13758 | LOW | 3.5 | 0.3% | Nov 27, 2025 | Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, throu... |
| CVE-2025-66040 | LOW | 3.6 | 0.1% | Nov 27, 2025 | Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vuln... |
| CVE-2025-65681 | LOW | 3.3 | 0.2% | Nov 26, 2025 | An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers ... |
| CVE-2025-20373 | LOW | 2.7 | 0.2% | Nov 26, 2025 | In Splunk Add-on for Palo Alto Networks versions below 2.0.2, the add-on exposes client secrets in plain text in the _in... |
| CVE-2025-55174 | LOW | 3.2 | 0.1% | Nov 26, 2025 | In KDE Skanpage before 25.08.0, an attempt at file overwrite can result in the contents of the new file at the beginning... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now