2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65581 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improp... |
| CVE-2025-46296 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privile... |
| CVE-2025-46294 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumerat... |
| CVE-2025-68116 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 2.7.1 are vulnerable to Stored Cross-Site ... |
| CVE-2025-62862 | MEDIUM | 4.6 | 0.1% | Dec 16, 2025 | Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.... |
| CVE-2025-59935 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an una... |
| CVE-2025-29231 | MEDIUM | 6.1 | 0.2% | Dec 16, 2025 | A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0.26 allows attackers... |
| CVE-2025-68269 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH |
| CVE-2025-68268 | MEDIUM | 6.1 | 0.2% | Dec 16, 2025 | In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page |
| CVE-2025-68267 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token in... |
| CVE-2025-68166 | MEDIUM | 6.1 | 0.2% | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab |
| CVE-2025-68165 | MEDIUM | 6.1 | 3.5% | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup |
| CVE-2025-68163 | MEDIUM | 4.8 | 0.2% | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page |
| CVE-2025-65427 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | An issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not impleme... |
| CVE-2025-64012 | MEDIUM | 4.3 | 0.3% | Dec 16, 2025 | InvoicePlane commit debb446c is vulnerable to Incorrect Access Control. The invoices/view handler fails to verify owners... |
| CVE-2025-62329 | MEDIUM | 5.6 | 0.2% | Dec 16, 2025 | HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which ma... |
| CVE-2025-14432 | MEDIUM | 4.9 | 0.4% | Dec 16, 2025 | In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC... |
| CVE-2025-68223 | MEDIUM | 5.5 | 0.1% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/radeon: delete radeon_fence_process in is_signa... |
| CVE-2025-68214 | MEDIUM | 4.7 | 0.1% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: timers: Fix NULL function pointer race in timer_shu... |
| CVE-2025-68211 | MEDIUM | 5.5 | 0.1% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksm: use range-walk function to jump over holes in ... |
| CVE-2025-65076 | MEDIUM | 6.1 | 0.3% | Dec 16, 2025 | WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Ser... |
| CVE-2025-65075 | MEDIUM | 6.5 | 0.3% | Dec 16, 2025 | WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Ser... |
| CVE-2025-14780 | MEDIUM | 6.3 | 0.2% | Dec 16, 2025 | A vulnerability was detected in Xiongwei Smart Catering Cloud Platform 2.1.6446.28761. The affected element is an unknow... |
| CVE-2025-14443 | MEDIUM | 6.4 | 0.3% | Dec 16, 2025 | A flaw was found in ose-openshift-apiserver. This vulnerability allows internal network enumeration, service discovery, ... |
| CVE-2025-13741 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin fo... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now