2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64464 | HIGH | 8.5 | 0.1% | Dec 18, 2025 | There is an out of bounds read vulnerability in NI LabVIEW in lvre!VisaWriteFromFile() when parsing a corrupted VI file.... |
| CVE-2025-64463 | HIGH | 8.5 | 0.1% | Dec 18, 2025 | There is an out of bounds read vulnerability in NI LabVIEW in LVResource::DetachResource() when parsing a corrupted VI f... |
| CVE-2025-64462 | HIGH | 8.5 | 0.1% | Dec 18, 2025 | There is an out of bounds read vulnerability in NI LabVIEW in LVResFile::RGetMemFileHandle() when parsing a corrupted VI... |
| CVE-2025-64461 | HIGH | 8.5 | 0.1% | Dec 18, 2025 | There is an out of bounds write vulnerability in NI LabVIEW in mgocre_SH_25_3!RevBL() when parsing a corrupted VI file. ... |
| CVE-2025-63757 | HIGH | 7.5 | 0.3% | Dec 18, 2025 | Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0. |
| CVE-2025-1031 | HIGH | 7.5 | 0.3% | Dec 18, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Utarit Informatics Services Inc. SoliClub allows Funct... |
| CVE-2025-1030 | HIGH | 7.5 | 0.3% | Dec 18, 2025 | Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Utarit Informatics Services Inc. Soli... |
| CVE-2025-1029 | HIGH | 7.5 | 0.2% | Dec 18, 2025 | Use of Hard-coded Credentials vulnerability in Utarit Information Services Inc. SoliClub allows Read Sensitive Constants... |
| CVE-2025-14861 | HIGH | 8.8 | 0.3% | Dec 18, 2025 | Memory safety bugs present in Firefox 146. Some of these bugs showed evidence of memory corruption and we presume that w... |
| CVE-2025-40898 | HIGH | 8.1 | 0.3% | Dec 18, 2025 | A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validatio... |
| CVE-2025-40892 | HIGH | 8.9 | 0.2% | Dec 18, 2025 | A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an... |
| CVE-2025-14437 | HIGH | 7.5 | 2.0% | Dec 18, 2025 | The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ... |
| CVE-2025-14364 | HIGH | 8.8 | 0.3% | Dec 18, 2025 | The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized modification of data, loss of data, and privil... |
| CVE-2025-13641 | HIGH | 8.8 | 0.7% | Dec 18, 2025 | The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclu... |
| CVE-2025-14874 | HIGH | 7.5 | 0.6% | Dec 18, 2025 | A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header t... |
| CVE-2025-6326 | HIGH | 8.1 | 0.3% | Dec 18, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-6324 | HIGH | 7.1 | 0.1% | Dec 18, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MatrixAddons Easy ... |
| CVE-2025-66119 | HIGH | 7.1 | 0.1% | Dec 18, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel hostel ... |
| CVE-2025-66118 | HIGH | 7.1 | 0.1% | Dec 18, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Sprout Cl... |
| CVE-2025-66117 | HIGH | 7.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in Ays Pro Easy Form easy-form allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2025-66116 | HIGH | 7.5 | 0.2% | Dec 18, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in UserElements Ultimate Member Widgets for Elementor ul... |
| CVE-2025-66102 | HIGH | 7.1 | 0.1% | Dec 18, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision FV Ant... |
| CVE-2025-66088 | HIGH | 7.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in Property Hive PropertyHive propertyhive allows Exploiting Incorrectly Configured ... |
| CVE-2025-66070 | HIGH | 7.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2025-66054 | HIGH | 7.5 | 0.2% | Dec 18, 2025 | Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access C... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now