2025 CVE Vulnerabilities
45,322 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34421 | HIGH | 7.8 | 0.2% | Dec 10, 2025 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe... |
| CVE-2025-34420 | HIGH | 7.8 | 0.1% | Dec 10, 2025 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe... |
| CVE-2025-34419 | HIGH | 7.8 | 0.1% | Dec 10, 2025 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe... |
| CVE-2025-34418 | HIGH | 7.8 | 0.1% | Dec 10, 2025 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe... |
| CVE-2025-34417 | HIGH | 7.8 | 0.1% | Dec 10, 2025 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe... |
| CVE-2025-34416 | HIGH | 7.8 | 0.1% | Dec 10, 2025 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe... |
| CVE-2025-34410 | HIGH | 7.1 | 0.1% | Dec 10, 2025 | 1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the Change Username functi... |
| CVE-2025-34395 | HIGH | 7.5 | 0.6% | Dec 10, 2025 | Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting ser... |
| CVE-2025-13155 | HIGH | 8.5 | 0.1% | Dec 10, 2025 | An improper permissions vulnerability was reported in Lenovo Baiying Client that could allow a local authenticated user ... |
| CVE-2025-13152 | HIGH | 7.8 | 0.1% | Dec 10, 2025 | A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that co... |
| CVE-2025-12046 | HIGH | 7.8 | 0.1% | Dec 10, 2025 | A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a lo... |
| CVE-2025-8110 | HIGH | 8.8 | 76.5% | Dec 10, 2025 | Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code. |
| CVE-2025-41358 | HIGH | 8.3 | 0.3% | Dec 10, 2025 | Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulne... |
| CVE-2025-7073 | HIGH | 7.8 | 0.1% | Dec 10, 2025 | A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privil... |
| CVE-2025-66675 | HIGH | 8.2 | 0.5% | Dec 10, 2025 | Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. Thi... |
| CVE-2025-14390 | HIGH | 8.8 | 0.4% | Dec 10, 2025 | The Video Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in version <= 5.0.4. This is due to ... |
| CVE-2025-1161 | HIGH | 7.1 | 0.2% | Dec 10, 2025 | Incorrect Use of Privileged APIs vulnerability in NomySoft Information Technology Training and Consulting Inc. Nomysem a... |
| CVE-2025-12952 | HIGH | 8.7 | 0.3% | Dec 10, 2025 | A privilege escalation vulnerability exists in Google Cloud's Dialogflow CX. Dialogflow agent developers with Webhook e... |
| CVE-2025-9571 | HIGH | 8.7 | 0.4% | Dec 10, 2025 | A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion. A user with permissions to upload artifa... |
| CVE-2025-13073 | HIGH | 7.1 | 0.2% | Dec 10, 2025 | The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting... |
| CVE-2025-13072 | HIGH | 7.1 | 0.2% | Dec 10, 2025 | The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting... |
| CVE-2025-13339 | HIGH | 7.5 | 2.2% | Dec 10, 2025 | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and in... |
| CVE-2025-67507 | HIGH | 8.1 | 0.3% | Dec 10, 2025 | Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 cont... |
| CVE-2025-67501 | HIGH | 8.8 | 0.4% | Dec 10, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below... |
| CVE-2025-61813 | HIGH | 7.4 | 0.5% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now