2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67740 | MEDIUM | 5.3 | 0.2% | Dec 11, 2025 | In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata |
| CVE-2025-59803 | MEDIUM | 5.3 | 0.2% | Dec 11, 2025 | Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker can embed triggers (e.g.,... |
| CVE-2025-55311 | MEDIUM | 6.5 | 0.2% | Dec 11, 2025 | An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF ... |
| CVE-2025-55309 | MEDIUM | 6.7 | 0.1% | Dec 11, 2025 | An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF ... |
| CVE-2025-55308 | MEDIUM | 6.7 | 0.1% | Dec 11, 2025 | An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. A crafted PDF containing... |
| CVE-2025-14519 | MEDIUM | 5.4 | 0.2% | Dec 11, 2025 | A security flaw has been discovered in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. This issue affects so... |
| CVE-2025-14517 | MEDIUM | 5.3 | 0.2% | Dec 11, 2025 | A vulnerability was determined in Yalantis uCrop 2.2.11. This affects the function UCropActivity of the file AndroidMan... |
| CVE-2025-64995 | MEDIUM | 6.7 | 0.1% | Dec 11, 2025 | A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Exchan... |
| CVE-2025-64994 | MEDIUM | 6.7 | 0.2% | Dec 11, 2025 | A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-... |
| CVE-2025-46266 | MEDIUM | 6.5 | 0.2% | Dec 11, 2025 | A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior versi... |
| CVE-2025-12687 | MEDIUM | 6.5 | 0.2% | Dec 11, 2025 | A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior versi... |
| CVE-2025-14512 | MEDIUM | 6.5 | 0.5% | Dec 11, 2025 | A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer ov... |
| CVE-2025-4097 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and ... |
| CVE-2025-11984 | MEDIUM | 6.8 | 0.3% | Dec 11, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.1 before 18.4.6, 18.5 before 18.5.4, and 1... |
| CVE-2025-11247 | MEDIUM | 4.3 | 0.2% | Dec 11, 2025 | GitLab has remediated an issue in GitLab EE affecting all versions from 13.2 before 18.4.6, 18.5 before 18.5.4, and 18.6... |
| CVE-2025-9436 | MEDIUM | 6.4 | 0.2% | Dec 11, 2025 | The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `trust... |
| CVE-2025-14157 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18... |
| CVE-2025-13978 | MEDIUM | 4.3 | 0.3% | Dec 11, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.4.6, 18.5 before 18.5.4, and 1... |
| CVE-2025-10163 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | The List category posts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘starting_with’ parameter... |
| CVE-2025-14485 | MEDIUM | 5 | 1.6% | Dec 11, 2025 | A weakness has been identified in EFM ipTIME A3004T 14.19.0. This vulnerability affects the function show_debug_screen o... |
| CVE-2025-11467 | MEDIUM | 5.8 | 0.2% | Dec 11, 2025 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is... |
| CVE-2025-67720 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | Pyrofork is a modern, asynchronous MTProto API framework. Versions 2.3.68 and earlier do not properly sanitize filenames... |
| CVE-2025-67717 | MEDIUM | 4.3 | 0.2% | Dec 11, 2025 | ZITADEL is an open-source identity infrastructure tool. Versions 2.44.0 through 3.4.4 and 4.0.0-rc.1 through 4.7.1 discl... |
| CVE-2025-67716 | MEDIUM | 5.7 | 0.2% | Dec 11, 2025 | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions 4.9.0 through ... |
| CVE-2025-67713 | MEDIUM | 6.1 | 0.2% | Dec 11, 2025 | Miniflux 2 is an open source feed reader. Versions 2.2.14 and below treat redirect_url as safe when url.Parse(...).IsAbs... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now