2025 CVE Vulnerabilities
45,322 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14523 | HIGH | 8.2 | 0.5% | Dec 11, 2025 | A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for ... |
| CVE-2025-13003 | HIGH | 7.6 | 0.2% | Dec 11, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Aksis Computer Services and Consulting Inc. AxOnboard ... |
| CVE-2025-64993 | HIGH | 7.2 | 0.8% | Dec 11, 2025 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-ConfigMgr... |
| CVE-2025-64992 | HIGH | 7.2 | 0.8% | Dec 11, 2025 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-Pau... |
| CVE-2025-64991 | HIGH | 7.2 | 0.8% | Dec 11, 2025 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-PatchInsi... |
| CVE-2025-64990 | HIGH | 7.2 | 0.7% | Dec 11, 2025 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-... |
| CVE-2025-64989 | HIGH | 7.2 | 1.0% | Dec 11, 2025 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-... |
| CVE-2025-64988 | HIGH | 7.2 | 1.0% | Dec 11, 2025 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-Get... |
| CVE-2025-64987 | HIGH | 7.2 | 1.0% | Dec 11, 2025 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-... |
| CVE-2025-64986 | HIGH | 7.2 | 1.1% | Dec 11, 2025 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-... |
| CVE-2025-44016 | HIGH | 8.8 | 0.3% | Dec 11, 2025 | A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior versi... |
| CVE-2025-64701 | HIGH | 8.5 | 0.1% | Dec 11, 2025 | QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability, which may allow a user... |
| CVE-2025-12029 | HIGH | 8 | 0.5% | Dec 11, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and ... |
| CVE-2025-67738 | HIGH | 8.5 | 0.3% | Dec 11, 2025 | squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module a... |
| CVE-2025-8405 | HIGH | 7.7 | 0.5% | Dec 11, 2025 | GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5.... |
| CVE-2025-12716 | HIGH | 8.7 | 0.4% | Dec 11, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.4.6, 18.5 before 18.5.4, and 1... |
| CVE-2025-12562 | HIGH | 7.5 | 0.8% | Dec 11, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and ... |
| CVE-2025-67719 | HIGH | 8.5 | 0.1% | Dec 11, 2025 | Ibexa is a composable end-to-end DXP (Digital Experience Platform). Versions 5.0.0-beta1 through 5.0.3 do not have passw... |
| CVE-2025-67718 | HIGH | 8.7 | 0.3% | Dec 11, 2025 | Form.io is a combined Form and API platform for Serverless applications. Versions 3.5.6 and below and 4.0.0-rc.1 through... |
| CVE-2025-67644 | HIGH | 7.8 | 2.1% | Dec 11, 2025 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, ... |
| CVE-2025-67509 | HIGH | 8.2 | 0.3% | Dec 10, 2025 | Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which... |
| CVE-2025-67505 | HIGH | 8.4 | 0.2% | Dec 10, 2025 | Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race ... |
| CVE-2025-66628 | HIGH | 7.5 | 0.5% | Dec 10, 2025 | ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the T... |
| CVE-2025-66474 | HIGH | 8.8 | 1.0% | Dec 10, 2025 | XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) int... |
| CVE-2025-66473 | HIGH | 7.5 | 0.4% | Dec 10, 2025 | XWiki is an open-source wiki software platform. Versions 16.10.10 and below, 17.0.0-rc-1 through 17.4.3 and 17.5.0-rc-1 ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now