2025 CVE Vulnerabilities
45,322 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61812 | HIGH | 8.4 | 4.7% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that... |
| CVE-2025-61810 | HIGH | 8.4 | 9.5% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerabili... |
| CVE-2025-67494 | HIGH | 8.6 | 0.5% | Dec 9, 2025 | ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, f... |
| CVE-2025-66645 | HIGH | 7.5 | 1.0% | Dec 9, 2025 | NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App.... |
| CVE-2025-65513 | HIGH | 7.5 | 0.4% | Dec 9, 2025 | fetch-mcp v1.0.2 and before is vulnerable to Server-Side Request Forgery (SSRF) vulnerability, which allows attackers to... |
| CVE-2025-67488 | HIGH | 8.8 | 0.4% | Dec 9, 2025 | SiYuan is self-hosted, open source personal knowledge management software. Versions 0.0.0-20251202123337-6ef83b42c7ce an... |
| CVE-2025-66626 | HIGH | 7.5 | 0.6% | Dec 9, 2025 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Version... |
| CVE-2025-64899 | HIGH | 7.8 | 0.5% | Dec 9, 2025 | Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by... |
| CVE-2025-64785 | HIGH | 7.8 | 0.5% | Dec 9, 2025 | Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by... |
| CVE-2025-13743 | HIGH | 7.5 | 0.2% | Dec 9, 2025 | Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serializatio... |
| CVE-2025-66457 | HIGH | 8.8 | 0.7% | Dec 9, 2025 | Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communi... |
| CVE-2025-66214 | HIGH | 8.8 | 0.3% | Dec 9, 2025 | Ladybug adds message-based debugging, unit, system, and regression testing to Java applications. Versions prior to 3.0-2... |
| CVE-2025-65573 | HIGH | 8.8 | 0.3% | Dec 9, 2025 | Cross Site Request Forgery (CSRF) vulnerability in AllskyTeam AllSky v2024.12.06_06 allows remote attackers to cause a d... |
| CVE-2025-11531 | HIGH | 8.8 | 0.3% | Dec 9, 2025 | HP System Event Utility and Omen Gaming Hub might allow execution of certain files outside of their restricted paths. T... |
| CVE-2025-65594 | HIGH | 8.1 | 0.3% | Dec 9, 2025 | OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privil... |
| CVE-2025-64893 | HIGH | 7.1 | 0.1% | Dec 9, 2025 | DNG SDK versions 1.7.0 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposur... |
| CVE-2025-64784 | HIGH | 7.1 | 0.2% | Dec 9, 2025 | DNG SDK versions 1.7.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory ... |
| CVE-2025-64783 | HIGH | 7.8 | 0.2% | Dec 9, 2025 | DNG SDK versions 1.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in ... |
| CVE-2025-64680 | HIGH | 7.8 | 0.4% | Dec 9, 2025 | Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
| CVE-2025-64679 | HIGH | 7.8 | 0.4% | Dec 9, 2025 | Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
| CVE-2025-64678 | HIGH | 8.8 | 1.0% | Dec 9, 2025 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut... |
| CVE-2025-64673 | HIGH | 7.8 | 0.3% | Dec 9, 2025 | Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally. |
| CVE-2025-64671 | HIGH | 7.8 | 0.3% | Dec 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at... |
| CVE-2025-64666 | HIGH | 7.5 | 1.0% | Dec 9, 2025 | Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a networ... |
| CVE-2025-64661 | HIGH | 7.8 | 0.3% | Dec 9, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now