2025 CVE Vulnerabilities
45,139 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68268 | MEDIUM | 6.1 | 0.2% | Dec 16, 2025 | In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page |
| CVE-2025-68267 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token in... |
| CVE-2025-68166 | MEDIUM | 6.1 | 0.2% | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab |
| CVE-2025-68165 | MEDIUM | 6.1 | 3.5% | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup |
| CVE-2025-68163 | MEDIUM | 4.8 | 0.2% | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page |
| CVE-2025-65427 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | An issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not impleme... |
| CVE-2025-64012 | MEDIUM | 4.3 | 0.3% | Dec 16, 2025 | InvoicePlane commit debb446c is vulnerable to Incorrect Access Control. The invoices/view handler fails to verify owners... |
| CVE-2025-62329 | MEDIUM | 5.6 | 0.2% | Dec 16, 2025 | HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which ma... |
| CVE-2025-14432 | MEDIUM | 4.9 | 0.3% | Dec 16, 2025 | In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC... |
| CVE-2025-68223 | MEDIUM | 5.5 | 0.1% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/radeon: delete radeon_fence_process in is_signa... |
| CVE-2025-68214 | MEDIUM | 4.7 | 0.1% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: timers: Fix NULL function pointer race in timer_shu... |
| CVE-2025-68211 | MEDIUM | 5.5 | 0.1% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksm: use range-walk function to jump over holes in ... |
| CVE-2025-65076 | MEDIUM | 6.1 | 0.3% | Dec 16, 2025 | WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Ser... |
| CVE-2025-65075 | MEDIUM | 6.5 | 0.3% | Dec 16, 2025 | WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Ser... |
| CVE-2025-14780 | MEDIUM | 6.3 | 0.2% | Dec 16, 2025 | A vulnerability was detected in Xiongwei Smart Catering Cloud Platform 2.1.6446.28761. The affected element is an unknow... |
| CVE-2025-14443 | MEDIUM | 6.4 | 0.3% | Dec 16, 2025 | A flaw was found in ose-openshift-apiserver. This vulnerability allows internal network enumeration, service discovery, ... |
| CVE-2025-13741 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin fo... |
| CVE-2025-11220 | MEDIUM | 6.4 | 0.2% | Dec 16, 2025 | The Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Text Path widget in all... |
| CVE-2025-0836 | MEDIUM | 6.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in Milestone Systems XProtect VMS allows users with read-only access to Management S... |
| CVE-2025-68088 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Huger for Elementor huger-elementor allows Exploiting Incorrectly Confi... |
| CVE-2025-68087 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Modalier for Elementor modalier-elementor allows Exploiting Incorrectly... |
| CVE-2025-68086 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Reformer for Elementor reformer-elementor allows Exploiting Incorrectly... |
| CVE-2025-68085 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Buttoner for Elementor buttoner-elementor allows Exploiting Incorrectly... |
| CVE-2025-68084 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in Nitesh Ultimate Auction ultimate-auction allows Exploiting Incorrectly Configure... |
| CVE-2025-68083 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Meks Meks Quick Plugin Disabler meks-quick-plugin-disabler allows Cro... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now