2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68067 | HIGH | 7.5 | 0.3% | Dec 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68066 | HIGH | 7.5 | 0.3% | Dec 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68065 | HIGH | 7.5 | 0.3% | Dec 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68062 | HIGH | 7.5 | 0.3% | Dec 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68061 | HIGH | 7.5 | 0.3% | Dec 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68056 | HIGH | 8.5 | 0.2% | Dec 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LBG Z... |
| CVE-2025-68055 | HIGH | 8.5 | 0.3% | Dec 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Boo... |
| CVE-2025-68054 | HIGH | 8.5 | 0.2% | Dec 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Count... |
| CVE-2025-68053 | HIGH | 8.5 | 0.2% | Dec 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup xProm... |
| CVE-2025-67999 | HIGH | 7.6 | 0.4% | Dec 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stefano Lissa News... |
| CVE-2025-67962 | HIGH | 7.6 | 0.3% | Dec 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AIOSEO Plugin Team... |
| CVE-2025-67950 | HIGH | 8.5 | 0.3% | Dec 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi All In... |
| CVE-2025-66635 | HIGH | 8.6 | 0.5% | Dec 16, 2025 | Stack-based buffer overflow vulnerability exists in SEIKO EPSON Web Config. Specially crafted data input by a logged-in ... |
| CVE-2025-14252 | HIGH | 8.5 | 0.1% | Dec 16, 2025 | An Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary me... |
| CVE-2025-61976 | HIGH | 8.7 | 0.4% | Dec 16, 2025 | CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper check for unusual or exceptional conditions. If a rem... |
| CVE-2025-62848 | HIGH | 7.5 | 0.8% | Dec 16, 2025 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote ... |
| CVE-2025-62847 | HIGH | 7.5 | 0.8% | Dec 16, 2025 | An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP op... |
| CVE-2025-14749 | HIGH | 8.8 | 0.7% | Dec 16, 2025 | A vulnerability was identified in Ningyuanda TC155 57.0.2.0. This impacts an unknown function of the file /onvif/device_... |
| CVE-2025-67751 | HIGH | 7.2 | 0.3% | Dec 16, 2025 | ChurchCRM is an open-source church management system. Prior to version 6.5.0, a SQL injection vulnerability exists in th... |
| CVE-2025-67748 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missi... |
| CVE-2025-67747 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 are missing `marshal` and `types` ... |
| CVE-2025-67736 | HIGH | 7.2 | 6.1% | Dec 16, 2025 | The FreePBX module tts (Text to Speech) for FreePBX, an open-source web-based graphical user interface (GUI) that manage... |
| CVE-2025-67722 | HIGH | 7.8 | 0.1% | Dec 16, 2025 | FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and ... |
| CVE-2025-66449 | HIGH | 8.8 | 0.7% | Dec 16, 2025 | ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authentica... |
| CVE-2025-9460 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulner... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now