2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65009 | HIGH | 7.1 | 0.2% | Dec 18, 2025 | In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) admin password is stored in configuration file as plai... |
| CVE-2025-65007 | HIGH | 8.7 | 0.3% | Dec 18, 2025 | In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of authentication in the configuration cha... |
| CVE-2025-64469 | HIGH | 8.5 | 0.1% | Dec 18, 2025 | There is a stack-based buffer overflow vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corr... |
| CVE-2025-64468 | HIGH | 8.5 | 0.1% | Dec 18, 2025 | There is a use-after-free vulnerability in sentry!sentry_span_set_data() when parsing a corrupted VI file. This vulnera... |
| CVE-2025-64467 | HIGH | 8.5 | 0.1% | Dec 18, 2025 | There is an out of bounds read vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corrupted VI... |
| CVE-2025-64466 | HIGH | 8.5 | 0.1% | Dec 18, 2025 | There is an out of bounds read vulnerability in NI LabVIEW in lvre!ExecPostedProcRecPost() when parsing a corrupted VI f... |
| CVE-2025-64465 | HIGH | 8.5 | 0.1% | Dec 18, 2025 | There is an out of bounds read vulnerability in NI LabVIEW in lvre!DataSizeTDR() when parsing a corrupted VI file. This... |
| CVE-2025-64464 | HIGH | 8.5 | 0.1% | Dec 18, 2025 | There is an out of bounds read vulnerability in NI LabVIEW in lvre!VisaWriteFromFile() when parsing a corrupted VI file.... |
| CVE-2025-64463 | HIGH | 8.5 | 0.1% | Dec 18, 2025 | There is an out of bounds read vulnerability in NI LabVIEW in LVResource::DetachResource() when parsing a corrupted VI f... |
| CVE-2025-64462 | HIGH | 8.5 | 0.1% | Dec 18, 2025 | There is an out of bounds read vulnerability in NI LabVIEW in LVResFile::RGetMemFileHandle() when parsing a corrupted VI... |
| CVE-2025-64461 | HIGH | 8.5 | 0.1% | Dec 18, 2025 | There is an out of bounds write vulnerability in NI LabVIEW in mgocre_SH_25_3!RevBL() when parsing a corrupted VI file. ... |
| CVE-2025-63757 | HIGH | 7.5 | 0.3% | Dec 18, 2025 | Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0. |
| CVE-2025-1031 | HIGH | 7.5 | 0.3% | Dec 18, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Utarit Informatics Services Inc. SoliClub allows Funct... |
| CVE-2025-1030 | HIGH | 7.5 | 0.3% | Dec 18, 2025 | Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Utarit Informatics Services Inc. Soli... |
| CVE-2025-1029 | HIGH | 7.5 | 0.2% | Dec 18, 2025 | Use of Hard-coded Credentials vulnerability in Utarit Information Services Inc. SoliClub allows Read Sensitive Constants... |
| CVE-2025-14861 | HIGH | 8.8 | 0.2% | Dec 18, 2025 | Memory safety bugs present in Firefox 146. Some of these bugs showed evidence of memory corruption and we presume that w... |
| CVE-2025-40898 | HIGH | 8.1 | 0.3% | Dec 18, 2025 | A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validatio... |
| CVE-2025-40892 | HIGH | 8.9 | 0.2% | Dec 18, 2025 | A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an... |
| CVE-2025-14437 | HIGH | 7.5 | 2.0% | Dec 18, 2025 | The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ... |
| CVE-2025-14364 | HIGH | 8.8 | 0.3% | Dec 18, 2025 | The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized modification of data, loss of data, and privil... |
| CVE-2025-13641 | HIGH | 8.8 | 0.7% | Dec 18, 2025 | The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclu... |
| CVE-2025-14874 | HIGH | 7.5 | 0.4% | Dec 18, 2025 | A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header t... |
| CVE-2025-6326 | HIGH | 8.1 | 0.3% | Dec 18, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-6324 | HIGH | 7.1 | 0.1% | Dec 18, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MatrixAddons Easy ... |
| CVE-2025-66119 | HIGH | 7.1 | 0.1% | Dec 18, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel hostel ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now