2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68365 | MEDIUM | 5.5 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize allocated memory before use K... |
| CVE-2025-68358 | MEDIUM | 5.5 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix racy bitfield write in btrfs_clear_space... |
| CVE-2025-68351 | MEDIUM | 5.5 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: exfat: fix refcount leak in exfat_find Fix refcoun... |
| CVE-2025-64641 | MEDIUM | 4.1 | 0.1% | Dec 24, 2025 | Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post ... |
| CVE-2025-13767 | MEDIUM | 4.3 | 0.2% | Dec 24, 2025 | Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user ch... |
| CVE-2025-13407 | MEDIUM | 6.8 | 0.3% | Dec 24, 2025 | The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files throug... |
| CVE-2025-15052 | MEDIUM | 5.4 | 0.2% | Dec 24, 2025 | A vulnerability was detected in code-projects Student Information System 1.0. This vulnerability affects unknown code of... |
| CVE-2025-14421 | MEDIUM | 5.5 | 0.1% | Dec 23, 2025 | pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allo... |
| CVE-2025-14411 | MEDIUM | 5.5 | 0.1% | Dec 23, 2025 | Soda PDF Desktop PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows rem... |
| CVE-2025-14410 | MEDIUM | 5.5 | 0.1% | Dec 23, 2025 | Soda PDF Desktop PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows rem... |
| CVE-2025-14407 | MEDIUM | 5.5 | 0.1% | Dec 23, 2025 | Soda PDF Desktop PDF File Parsing Memory Corruption Information Disclosure Vulnerability. This vulnerability allows remo... |
| CVE-2025-14405 | MEDIUM | 6.8 | 0.3% | Dec 23, 2025 | PDFsam Enhanced Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows phy... |
| CVE-2025-13698 | MEDIUM | 4.5 | 0.5% | Dec 23, 2025 | Deciso OPNsense diag_backup.php filename Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability a... |
| CVE-2025-65713 | MEDIUM | 4 | 0.4% | Dec 23, 2025 | Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully val... |
| CVE-2025-65410 | MEDIUM | 6.2 | 0.2% | Dec 23, 2025 | A stack overflow in the src/main.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) v... |
| CVE-2025-45493 | MEDIUM | 6.5 | 0.8% | Dec 23, 2025 | Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the iface parameter in the action_bandwidth function. |
| CVE-2025-68340 | MEDIUM | 5.5 | 0.1% | Dec 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: team: Move team device type change at the end of te... |
| CVE-2025-66845 | MEDIUM | 6.1 | 0.2% | Dec 23, 2025 | A reflected Cross-Site Scripting (XSS) vulnerability has been identified in TechStore version 1.0. The user_name endpoin... |
| CVE-2025-68559 | MEDIUM | 6.5 | 0.1% | Dec 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem... |
| CVE-2025-68557 | MEDIUM | 4.3 | 0.2% | Dec 23, 2025 | Missing Authorization vulnerability in Vikas Ratudi Chakra test chakra-test allows Exploiting Incorrectly Configured Acc... |
| CVE-2025-68556 | MEDIUM | 5.3 | 0.2% | Dec 23, 2025 | Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrect... |
| CVE-2025-68551 | MEDIUM | 6.5 | 0.2% | Dec 23, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vikas Ratudi VPSUForm v-form... |
| CVE-2025-68548 | MEDIUM | 6.5 | 0.1% | Dec 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Res... |
| CVE-2025-14635 | MEDIUM | 6.4 | 0.3% | Dec 23, 2025 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_page_custom... |
| CVE-2025-14000 | MEDIUM | 6.4 | 0.2% | Dec 23, 2025 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now