2025 CVE Vulnerabilities
45,322 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67518 | HIGH | 8.5 | 0.3% | Dec 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Accor... |
| CVE-2025-67517 | HIGH | 8.5 | 0.3% | Dec 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in artplacer ArtPlace... |
| CVE-2025-67516 | HIGH | 8.5 | 0.3% | Dec 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store ... |
| CVE-2025-67515 | HIGH | 8.8 | 0.4% | Dec 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-67487 | HIGH | 8.6 | 0.3% | Dec 9, 2025 | Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Versions 2.40.0 and be... |
| CVE-2025-67472 | HIGH | 8.8 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita mee... |
| CVE-2025-66627 | HIGH | 7.8 | 0.1% | Dec 9, 2025 | Wasmi is a WebAssembly interpreter focused on constrained and embedded systems. In versions 0.41.0, 0.41.1, 0.42.0 throu... |
| CVE-2025-66622 | HIGH | 7.5 | 0.3% | Dec 9, 2025 | matrix-sdk-base is the base component to build a Matrix client library. Versions 0.14.1 and prior are unable to handle r... |
| CVE-2025-66578 | HIGH | 7.5 | 0.2% | Dec 9, 2025 | xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Versions 3.1.3 contain an authent... |
| CVE-2025-66507 | HIGH | 7.5 | 0.4% | Dec 9, 2025 | 1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.13 and below allow an unauth... |
| CVE-2025-66271 | HIGH | 8.4 | 0.1% | Dec 9, 2025 | Clone for Windows provided by ELECOM CO.,LTD. registers a Windows service with an unquoted file path. A user with the wr... |
| CVE-2025-63076 | HIGH | 7.5 | 0.4% | Dec 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-63074 | HIGH | 7.5 | 0.5% | Dec 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-63062 | HIGH | 7.5 | 0.5% | Dec 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-63036 | HIGH | 7.5 | 0.4% | Dec 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-63030 | HIGH | 7.1 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal New User Approve new-user-approve allows Cross Site Reques... |
| CVE-2025-63003 | HIGH | 7.5 | 0.4% | Dec 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-62093 | HIGH | 8.5 | 0.3% | Dec 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Image... |
| CVE-2025-61075 | HIGH | 8.1 | 0.5% | Dec 9, 2025 | Multiple Incorrect Access Control vulnerabilities in adata Software GmbH Mitarbeiterportal 2.15.2.0 allow remote authent... |
| CVE-2025-5471 | HIGH | 7.8 | 0.2% | Dec 9, 2025 | Uncontrolled Search Path Element vulnerability in Yandex Telemost on MacOS allows Search Order Hijacking.This issue affe... |
| CVE-2025-5470 | HIGH | 7.3 | 0.1% | Dec 9, 2025 | Uncontrolled Search Path Element vulnerability in Yandex Disk on MacOS allows Search Order Hijacking.This issue affects ... |
| CVE-2025-5469 | HIGH | 7.3 | 0.1% | Dec 9, 2025 | Uncontrolled Search Path Element vulnerability in Yandex Messenger on MacOS allows Search Order Hijacking.This issue aff... |
| CVE-2025-59030 | HIGH | 7.5 | 0.5% | Dec 9, 2025 | An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP. |
| CVE-2025-49351 | HIGH | 7.1 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Valentin Agachi Create Posts & Terms create-posts-terms allows Stored... |
| CVE-2025-49347 | HIGH | 7.1 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Jupitercow WP sIFR wp-sifr allows Stored XSS.This issue affects WP sI... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now