2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67780 | MEDIUM | 4.2 | 0.1% | Dec 11, 2025 | SpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on Mini1_prod2) allow administrative actions via un... |
| CVE-2025-66452 | MEDIUM | 6.1 | 0.2% | Dec 11, 2025 | LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, there is no handler for JSON parsing... |
| CVE-2025-66451 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when creating prompts, JSON requests... |
| CVE-2025-66450 | MEDIUM | 5.4 | 0.2% | Dec 11, 2025 | LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when a user posts a question, the ic... |
| CVE-2025-34504 | MEDIUM | 6.1 | 0.3% | Dec 11, 2025 | KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the ... |
| CVE-2025-34499 | MEDIUM | 6.9 | 0.4% | Dec 11, 2025 | AnyDesk 7.0.15 and 9.0.1 contains an unquoted service path vulnerability that allows local non-privileged users to poten... |
| CVE-2025-13668 | MEDIUM | 6.7 | 0.1% | Dec 11, 2025 | A potential security vulnerability in Quartus® Prime Pro Edition Design Software may allow escalation of privilege. |
| CVE-2025-64702 | MEDIUM | 5.3 | 0.3% | Dec 11, 2025 | quic-go is an implementation of the QUIC protocol in Go. Versions 0.56.0 and below are vulnerable to excessive memory al... |
| CVE-2025-55816 | MEDIUM | 6.1 | 0.2% | Dec 11, 2025 | HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file. |
| CVE-2025-14293 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 ... |
| CVE-2025-13664 | MEDIUM | 6.7 | 0.1% | Dec 11, 2025 | A potential security vulnerability in Quartus® Prime Standard Edition Design Software may allow escalation of privilege. |
| CVE-2025-13663 | MEDIUM | 6.7 | 0.1% | Dec 11, 2025 | Under certain circumstances, the Quartus Prime Pro Installer for Windows does not check the permissions of the Quartus t... |
| CVE-2025-55183 | MEDIUM | 5.3 | 62.4% | Dec 11, 2025 | An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 1... |
| CVE-2025-36938 | MEDIUM | 6.8 | 0.1% | Dec 11, 2025 | In U-Boot of append_uint32_le(), there is a possible fault injection due to a logic error in the code. This could lead t... |
| CVE-2025-36929 | MEDIUM | 5.5 | 0.1% | Dec 11, 2025 | In AreFencesRegistered of gxp_fence_manager.cc, there is a possible information leak due to improper input validation. T... |
| CVE-2025-36922 | MEDIUM | 6.7 | 0.1% | Dec 11, 2025 | In bigo_map of bigo_iommu.c, there is a possible information disclosure due to a use after free. This could lead to loc... |
| CVE-2025-36921 | MEDIUM | 5.5 | 0.1% | Dec 11, 2025 | In ProtocolPsUnthrottleApn() of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds ch... |
| CVE-2025-36917 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | In SwDcpItg of up_L2commonPdcpSecurity.cpp, there is a possible denial of service due to an incorrect bounds check. This... |
| CVE-2025-36912 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | In cellular modem, there is a possible denial of service due to a logic error in the code. This could lead to remote den... |
| CVE-2025-36889 | MEDIUM | 5.5 | 0.1% | Dec 11, 2025 | In onCreateTasks of CameraActivity.java, there is a possible permission bypass due to a confused deputy. This could lead... |
| CVE-2025-13211 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to cause a denial of service in the email ... |
| CVE-2025-13148 | MEDIUM | 6.5 | 0.2% | Dec 11, 2025 | IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another us... |
| CVE-2025-14531 | MEDIUM | 4.3 | 0.3% | Dec 11, 2025 | A vulnerability was found in code-projects Rental Management System 2.0. This affects an unknown function of the file Tr... |
| CVE-2025-14046 | MEDIUM | 6.1 | 0.3% | Dec 11, 2025 | An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed user-supplied ... |
| CVE-2025-67741 | MEDIUM | 5.4 | 0.4% | Dec 11, 2025 | In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now