2025 CVE Vulnerabilities
45,139 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34441 | HIGH | 7.5 | 0.7% | Dec 17, 2025 | AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Response... |
| CVE-2025-34438 | HIGH | 8.1 | 0.2% | Dec 17, 2025 | AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permi... |
| CVE-2025-34437 | HIGH | 8.8 | 0.4% | Dec 17, 2025 | AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The... |
| CVE-2025-34436 | HIGH | 8.8 | 0.4% | Dec 17, 2025 | AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due... |
| CVE-2025-67174 | HIGH | 7.5 | 1.1% | Dec 17, 2025 | A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a ... |
| CVE-2025-67171 | HIGH | 7.5 | 0.7% | Dec 17, 2025 | Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via d... |
| CVE-2025-66953 | HIGH | 8.8 | 0.3% | Dec 17, 2025 | CSRF vulnerability in narda miteq Uplink Power Contril Unit UPC2 v.1.17 allows a remote attacker to execute arbitrary co... |
| CVE-2025-66395 | HIGH | 8.8 | 0.3% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in th... |
| CVE-2025-67172 | HIGH | 7.2 | 0.8% | Dec 17, 2025 | RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_specia... |
| CVE-2025-66923 | HIGH | 7.2 | 0.5% | Dec 17, 2025 | A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remot... |
| CVE-2025-65203 | HIGH | 7.1 | 0.1% | Dec 17, 2025 | KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-e... |
| CVE-2025-67285 | HIGH | 7.3 | 0.2% | Dec 17, 2025 | A SQL injection vulnerability was found in the '/cts/admin/?page=zone' file of ITSourcecode COVID Tracking System Using ... |
| CVE-2025-66921 | HIGH | 7.2 | 0.5% | Dec 17, 2025 | A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows re... |
| CVE-2025-53919 | HIGH | 7.8 | 0.1% | Dec 17, 2025 | An issue was discovered in the Portrait Dell Color Management application through 3.3.008 for Dell monitors, It creates ... |
| CVE-2025-53398 | HIGH | 7.8 | 0.1% | Dec 17, 2025 | The Portrait Dell Color Management application 3.3.8 for Dell monitors has Insecure Permissions, |
| CVE-2025-43873 | HIGH | 8.7 | 0.3% | Dec 17, 2025 | Successful exploitation of these vulnerabilities could allow an attacker to modify firmware and gain full access to the ... |
| CVE-2025-14727 | HIGH | 8.7 | 0.4% | Dec 17, 2025 | A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software v... |
| CVE-2025-61736 | HIGH | 7.1 | 0.1% | Dec 17, 2025 | Successful exploitation of this vulnerability could result in the product failing to re-establish communication once the... |
| CVE-2025-14097 | HIGH | 7.2 | 0.4% | Dec 17, 2025 | A vulnerability in the application software of multiple Radiometer products may allow remote code execution and unauthor... |
| CVE-2025-14096 | HIGH | 8.4 | 0.1% | Dec 17, 2025 | A vulnerability exists in multiple Radiometer products that allow an attacker with physical access to the analyzer possi... |
| CVE-2025-14101 | HIGH | 7.1 | 0.2% | Dec 17, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in GG Soft Software Services Inc. PaperWork allows Exploi... |
| CVE-2025-11924 | HIGH | 7.5 | 0.4% | Dec 17, 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Obj... |
| CVE-2025-11901 | HIGH | 7 | 0.2% | Dec 17, 2025 | An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760... |
| CVE-2025-14305 | HIGH | 8.5 | 0.1% | Dec 17, 2025 | ListCheck.exe developed by Acer has a Local Privilege Escalation vulnerability. Authenticated local attackers can replac... |
| CVE-2025-14304 | HIGH | 7 | 0.3% | Dec 17, 2025 | Certain motherboard models developed by ASRock and its subsidiaries, ASRockRack and ASRockInd. has a Protection Mechanis... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now