2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68111 | HIGH | 7.2 | 0.3% | Dec 17, 2025 | ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability exists i... |
| CVE-2025-68110 | HIGH | 8.8 | 0.4% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an er... |
| CVE-2025-68109 | HIGH | 7.2 | 1.4% | Dec 17, 2025 | ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality doe... |
| CVE-2025-67877 | HIGH | 8.8 | 0.3% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a SQL injection vulnerability in the ... |
| CVE-2025-67873 | HIGH | 7.8 | 0.2% | Dec 17, 2025 | Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, Skipdata length is not bounds-checked, so a use... |
| CVE-2025-67792 | HIGH | 7.8 | 0.1% | Dec 17, 2025 | An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged ... |
| CVE-2025-67790 | HIGH | 7.5 | 0.3% | Dec 17, 2025 | An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. An unprivileged use... |
| CVE-2025-53000 | HIGH | 7.8 | 0.2% | Dec 17, 2025 | The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions... |
| CVE-2025-46291 | HIGH | 7.8 | 0.2% | Dec 17, 2025 | A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.2. An ... |
| CVE-2025-46281 | HIGH | 8.8 | 0.2% | Dec 17, 2025 | A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macO... |
| CVE-2025-43529 | HIGH | 8.8 | 8.8% | Dec 17, 2025 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and... |
| CVE-2025-66646 | HIGH | 7.5 | 0.6% | Dec 17, 2025 | RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ... |
| CVE-2025-66397 | HIGH | 8.3 | 0.3% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reload... |
| CVE-2025-66396 | HIGH | 7.2 | 0.3% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in th... |
| CVE-2025-34442 | HIGH | 7.5 | 0.7% | Dec 17, 2025 | AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata in... |
| CVE-2025-34441 | HIGH | 7.5 | 0.7% | Dec 17, 2025 | AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Response... |
| CVE-2025-34438 | HIGH | 8.1 | 0.3% | Dec 17, 2025 | AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permi... |
| CVE-2025-34437 | HIGH | 8.8 | 0.4% | Dec 17, 2025 | AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The... |
| CVE-2025-34436 | HIGH | 8.8 | 0.4% | Dec 17, 2025 | AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due... |
| CVE-2025-67174 | HIGH | 7.5 | 1.1% | Dec 17, 2025 | A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a ... |
| CVE-2025-67171 | HIGH | 7.5 | 0.7% | Dec 17, 2025 | Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via d... |
| CVE-2025-66953 | HIGH | 8.8 | 0.3% | Dec 17, 2025 | CSRF vulnerability in narda miteq Uplink Power Contril Unit UPC2 v.1.17 allows a remote attacker to execute arbitrary co... |
| CVE-2025-66395 | HIGH | 8.8 | 0.3% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in th... |
| CVE-2025-67172 | HIGH | 7.2 | 0.8% | Dec 17, 2025 | RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_specia... |
| CVE-2025-66923 | HIGH | 7.2 | 0.5% | Dec 17, 2025 | A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remot... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now