2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14322 | HIGH | 8 | 0.3% | Dec 9, 2025 | Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed... |
| CVE-2025-14309 | HIGH | 7.5 | 0.4% | Dec 9, 2025 | NULL Pointer Dereference vulnerability in ravynsoft ravynos.This issue affects ravynos: through 0.5.2. |
| CVE-2025-14307 | HIGH | 8.1 | 0.3% | Dec 9, 2025 | An insecure temporary file creation vulnerability exists in the AutoExtract component of Robocode version 1.9.3.6. The c... |
| CVE-2025-14286 | HIGH | 7.5 | 0.6% | Dec 9, 2025 | A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionalit... |
| CVE-2025-13662 | HIGH | 7.8 | 0.5% | Dec 9, 2025 | Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to ... |
| CVE-2025-13661 | HIGH | 8 | 1.1% | Dec 9, 2025 | Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write ... |
| CVE-2025-13659 | HIGH | 8.8 | 1.6% | Dec 9, 2025 | Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a... |
| CVE-2025-13604 | HIGH | 7.2 | 0.3% | Dec 9, 2025 | The Login Security, FireWall, Malware removal by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scrip... |
| CVE-2025-13428 | HIGH | 7.2 | 0.3% | Dec 9, 2025 | A vulnerability exists in the SecOps SOAR server. The custom integrations feature allowed an authenticated user with an ... |
| CVE-2025-13071 | HIGH | 7.1 | 0.2% | Dec 9, 2025 | The Custom Admin Menu WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back ... |
| CVE-2025-12807 | HIGH | 8.7 | 0.4% | Dec 9, 2025 | A security issue was discovered in DataMosaix Private Cloud, allowing users with low privilege to perform sensitive data... |
| CVE-2025-12705 | HIGH | 7.2 | 0.3% | Dec 9, 2025 | The Social Reviews & Recommendations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several param... |
| CVE-2025-12381 | HIGH | 7.8 | 0.1% | Dec 9, 2025 | Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, P... |
| CVE-2025-10655 | HIGH | 8.8 | 0.5% | Dec 9, 2025 | SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled para... |
| CVE-2025-66204 | HIGH | 8.1 | 0.4% | Dec 9, 2025 | WBCE CMS is a content management system. Version 1.6.4 contains a brute-force protection bypass where an attacker can in... |
| CVE-2025-65964 | HIGH | 8.8 | 0.6% | Dec 9, 2025 | n8n is an open source workflow automation platform. Versions 0.123.1 through 1.119.1 do not have adequate protections to... |
| CVE-2025-65271 | HIGH | 8.8 | 0.4% | Dec 8, 2025 | Client-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary te... |
| CVE-2025-14261 | HIGH | 7.1 | 0.3% | Dec 8, 2025 | The Litmus platform uses JWT for authentication and authorization, but the secret being used for signing the JWT is only... |
| CVE-2025-48625 | HIGH | 7 | 0.1% | Dec 8, 2025 | In multiple locations of UsbDataAdvancedProtectionHook.java, there is a possible way to access USB data when the screen ... |
| CVE-2025-48606 | HIGH | 7.8 | 0.1% | Dec 8, 2025 | In preparePackage of InstallPackageHelper.java, there is a possible way for an app to appear hidden upon installation wi... |
| CVE-2025-65795 | HIGH | 7.5 | 0.3% | Dec 8, 2025 | Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create ... |
| CVE-2025-65363 | HIGH | 7.2 | 5.8% | Dec 8, 2025 | Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute app... |
| CVE-2025-63721 | HIGH | 8.8 | 0.4% | Dec 8, 2025 | HummerRisk thru v1.5.0 is using a vulnerable Snakeyaml component, allowing attackers with normal user privileges to hit ... |
| CVE-2025-48639 | HIGH | 7.3 | 0.1% | Dec 8, 2025 | In DefaultTransitionHandler.java, there is a possible way to unknowingly grant permissions to an app due to a tapjacking... |
| CVE-2025-48638 | HIGH | 7.8 | 0.1% | Dec 8, 2025 | In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now