2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65203 | HIGH | 7.1 | 0.1% | Dec 17, 2025 | KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-e... |
| CVE-2025-67285 | HIGH | 7.3 | 0.2% | Dec 17, 2025 | A SQL injection vulnerability was found in the '/cts/admin/?page=zone' file of ITSourcecode COVID Tracking System Using ... |
| CVE-2025-66921 | HIGH | 7.2 | 0.5% | Dec 17, 2025 | A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows re... |
| CVE-2025-53919 | HIGH | 7.8 | 0.1% | Dec 17, 2025 | An issue was discovered in the Portrait Dell Color Management application through 3.3.008 for Dell monitors, It creates ... |
| CVE-2025-53398 | HIGH | 7.8 | 0.1% | Dec 17, 2025 | The Portrait Dell Color Management application 3.3.8 for Dell monitors has Insecure Permissions, |
| CVE-2025-43873 | HIGH | 8.7 | 0.3% | Dec 17, 2025 | Successful exploitation of these vulnerabilities could allow an attacker to modify firmware and gain full access to the ... |
| CVE-2025-14727 | HIGH | 8.7 | 0.4% | Dec 17, 2025 | A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software v... |
| CVE-2025-61736 | HIGH | 7.1 | 0.1% | Dec 17, 2025 | Successful exploitation of this vulnerability could result in the product failing to re-establish communication once the... |
| CVE-2025-14097 | HIGH | 7.2 | 0.4% | Dec 17, 2025 | A vulnerability in the application software of multiple Radiometer products may allow remote code execution and unauthor... |
| CVE-2025-14096 | HIGH | 8.4 | 0.1% | Dec 17, 2025 | A vulnerability exists in multiple Radiometer products that allow an attacker with physical access to the analyzer possi... |
| CVE-2025-14101 | HIGH | 7.1 | 0.2% | Dec 17, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in GG Soft Software Services Inc. PaperWork allows Exploi... |
| CVE-2025-11924 | HIGH | 7.5 | 0.4% | Dec 17, 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Obj... |
| CVE-2025-11901 | HIGH | 7 | 0.2% | Dec 17, 2025 | An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760... |
| CVE-2025-14305 | HIGH | 8.5 | 0.1% | Dec 17, 2025 | ListCheck.exe developed by Acer has a Local Privilege Escalation vulnerability. Authenticated local attackers can replac... |
| CVE-2025-14303 | HIGH | 7 | 0.3% | Dec 17, 2025 | Certain motherboard models developed by MSI has a Protection Mechanism Failure vulnerability. Because IOMMU was not prop... |
| CVE-2025-53524 | HIGH | 8.4 | 0.2% | Dec 17, 2025 | Fuji Electric Monitouch V-SFT-6 is vulnerable to an out-of-bounds write while processing a specially crafted project fi... |
| CVE-2025-14701 | HIGH | 7.1 | 0.3% | Dec 17, 2025 | An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated... |
| CVE-2025-14766 | HIGH | 8.8 | 3.2% | Dec 16, 2025 | Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exp... |
| CVE-2025-14765 | HIGH | 8.8 | 3.0% | Dec 16, 2025 | Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap ... |
| CVE-2025-68274 | HIGH | 7.5 | 0.5% | Dec 16, 2025 | SIPGO is a library for writing SIP services in the GO language. Starting in version 0.3.0 and prior to version 1.0.0-alp... |
| CVE-2025-52582 | HIGH | 7.5 | 0.3% | Dec 16, 2025 | An out-of-bounds read vulnerability exists in the Overlay::GrabOverlayFromPixelData functionality of Grassroot DICOM 3.0... |
| CVE-2025-8872 | HIGH | 7.1 | 0.3% | Dec 16, 2025 | On affected platforms running Arista EOS with OSPFv3 configured, a specially crafted packet can cause the OSFPv3 process... |
| CVE-2025-68156 | HIGH | 7.5 | 0.4% | Dec 16, 2025 | Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in E... |
| CVE-2025-68155 | HIGH | 7.5 | 0.6% | Dec 16, 2025 | @vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_find... |
| CVE-2025-68154 | HIGH | 8.1 | 13.0% | Dec 16, 2025 | systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` funct... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now