2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14761 | MEDIUM | 6 | 0.2% | Dec 17, 2025 | Missing cryptographic key commitment in the AWS SDK for PHP may allow a user with write access to the S3 bucket to intro... |
| CVE-2025-67074 | MEDIUM | 6.5 | 0.3% | Dec 17, 2025 | A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remot... |
| CVE-2025-65233 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ... |
| CVE-2025-34440 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validation of the siteRedire... |
| CVE-2025-34439 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | AVideo versions prior to 20.1 are vulnerable to an open redirect flaw due to missing validation of the cancelUri paramet... |
| CVE-2025-34435 | MEDIUM | 6.5 | 0.3% | Dec 17, 2025 | AVideo versions prior to 20.1 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated... |
| CVE-2025-14760 | MEDIUM | 6 | 0.1% | Dec 17, 2025 | Missing cryptographic key commitment in the AWS SDK for C++ may allow a user with write access to the S3 bucket to intro... |
| CVE-2025-14759 | MEDIUM | 6 | 0.1% | Dec 17, 2025 | Missing cryptographic key commitment in the Amazon S3 Encryption Client for .NET may allow a user with write access to t... |
| CVE-2025-67173 | MEDIUM | 6.8 | 0.2% | Dec 17, 2025 | A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrar... |
| CVE-2025-67170 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the... |
| CVE-2025-67168 | MEDIUM | 5.3 | 0.1% | Dec 17, 2025 | RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords. |
| CVE-2025-14081 | MEDIUM | 4.3 | 0.3% | Dec 17, 2025 | The Ultimate Member plugin for WordPress is vulnerable to Profile Privacy Setting Bypass in all versions up to, and incl... |
| CVE-2025-13537 | MEDIUM | 6.4 | 0.2% | Dec 17, 2025 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to multiple Stored Cross-Site Scri... |
| CVE-2025-13217 | MEDIUM | 6.4 | 0.3% | Dec 17, 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for W... |
| CVE-2025-12689 | MEDIUM | 6.5 | 0.2% | Dec 17, 2025 | Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for p... |
| CVE-2025-66924 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remot... |
| CVE-2025-65855 | MEDIUM | 6.6 | 0.1% | Dec 17, 2025 | The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-... |
| CVE-2025-26381 | MEDIUM | 6.5 | 0.3% | Dec 17, 2025 | Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to sensitive informati... |
| CVE-2025-62690 | MEDIUM | 6.1 | 0.1% | Dec 17, 2025 | Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to re... |
| CVE-2025-62190 | MEDIUM | 4.3 | 0.1% | Dec 17, 2025 | Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail... |
| CVE-2025-14095 | MEDIUM | 6.8 | 0.2% | Dec 17, 2025 | A "Privilege boundary violation" vulnerability is identified affecting multiple Radiometer Products. Exploitation of thi... |
| CVE-2025-14347 | MEDIUM | 6.3 | 0.2% | Dec 17, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Soft... |
| CVE-2025-14399 | MEDIUM | 4.3 | 0.1% | Dec 17, 2025 | The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery i... |
| CVE-2025-12496 | MEDIUM | 4.9 | 0.7% | Dec 17, 2025 | The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includin... |
| CVE-2025-14817 | MEDIUM | 6.5 | 0.2% | Dec 17, 2025 | The component com.transsion.tranfacmode.entrance.main.MainActivity in com.transsion.tranfacmode has no permission contro... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now