2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8110 | HIGH | 8.8 | 76.5% | Dec 10, 2025 | Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code. |
| CVE-2025-41358 | HIGH | 8.3 | 0.3% | Dec 10, 2025 | Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulne... |
| CVE-2025-7073 | HIGH | 7.8 | 0.1% | Dec 10, 2025 | A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privil... |
| CVE-2025-66675 | HIGH | 8.2 | 0.5% | Dec 10, 2025 | Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. Thi... |
| CVE-2025-14390 | HIGH | 8.8 | 0.4% | Dec 10, 2025 | The Video Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in version <= 5.0.4. This is due to ... |
| CVE-2025-1161 | HIGH | 7.1 | 0.2% | Dec 10, 2025 | Incorrect Use of Privileged APIs vulnerability in NomySoft Information Technology Training and Consulting Inc. Nomysem a... |
| CVE-2025-12952 | HIGH | 8.7 | 0.3% | Dec 10, 2025 | A privilege escalation vulnerability exists in Google Cloud's Dialogflow CX. Dialogflow agent developers with Webhook e... |
| CVE-2025-9571 | HIGH | 8.7 | 0.4% | Dec 10, 2025 | A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion. A user with permissions to upload artifa... |
| CVE-2025-13073 | HIGH | 7.1 | 0.1% | Dec 10, 2025 | The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting... |
| CVE-2025-13072 | HIGH | 7.1 | 0.1% | Dec 10, 2025 | The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting... |
| CVE-2025-13339 | HIGH | 7.5 | 2.1% | Dec 10, 2025 | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and in... |
| CVE-2025-67507 | HIGH | 8.1 | 0.3% | Dec 10, 2025 | Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 cont... |
| CVE-2025-67501 | HIGH | 8.8 | 0.4% | Dec 10, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below... |
| CVE-2025-61813 | HIGH | 7.4 | 0.5% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity ... |
| CVE-2025-61812 | HIGH | 8.4 | 3.7% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that... |
| CVE-2025-61810 | HIGH | 8.4 | 8.0% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerabili... |
| CVE-2025-67494 | HIGH | 8.6 | 0.5% | Dec 9, 2025 | ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, f... |
| CVE-2025-66645 | HIGH | 7.5 | 1.0% | Dec 9, 2025 | NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App.... |
| CVE-2025-65513 | HIGH | 7.5 | 0.4% | Dec 9, 2025 | fetch-mcp v1.0.2 and before is vulnerable to Server-Side Request Forgery (SSRF) vulnerability, which allows attackers to... |
| CVE-2025-67488 | HIGH | 8.8 | 0.4% | Dec 9, 2025 | SiYuan is self-hosted, open source personal knowledge management software. Versions 0.0.0-20251202123337-6ef83b42c7ce an... |
| CVE-2025-66626 | HIGH | 7.5 | 0.6% | Dec 9, 2025 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Version... |
| CVE-2025-64899 | HIGH | 7.8 | 0.4% | Dec 9, 2025 | Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by... |
| CVE-2025-64785 | HIGH | 7.8 | 0.4% | Dec 9, 2025 | Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by... |
| CVE-2025-13743 | HIGH | 7.5 | 0.2% | Dec 9, 2025 | Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serializatio... |
| CVE-2025-66457 | HIGH | 8.8 | 0.7% | Dec 9, 2025 | Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now