2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40331 | HIGH | 7.8 | 0.2% | Dec 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: sctp: Prevent TOCTOU out-of-bounds write For the f... |
| CVE-2025-40328 | HIGH | 8.8 | 0.2% | Dec 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in smb2_close_cached... |
| CVE-2025-2296 | HIGH | 8.4 | 0.7% | Dec 9, 2025 | EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successf... |
| CVE-2025-14333 | HIGH | 8.1 | 0.4% | Dec 9, 2025 | Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these b... |
| CVE-2025-14332 | HIGH | 7.3 | 0.3% | Dec 9, 2025 | Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption a... |
| CVE-2025-14329 | HIGH | 8.8 | 0.4% | Dec 9, 2025 | Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunde... |
| CVE-2025-14328 | HIGH | 8.8 | 0.4% | Dec 9, 2025 | Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunde... |
| CVE-2025-14327 | HIGH | 7.5 | 0.4% | Dec 9, 2025 | Spoofing issue in the Downloads Panel component. This vulnerability was fixed in Firefox 146, Thunderbird 146, Firefox E... |
| CVE-2025-14325 | HIGH | 7.3 | 0.3% | Dec 9, 2025 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140... |
| CVE-2025-14323 | HIGH | 8.8 | 0.4% | Dec 9, 2025 | Privilege escalation in the DOM: Notifications component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.3... |
| CVE-2025-14322 | HIGH | 8 | 0.3% | Dec 9, 2025 | Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed... |
| CVE-2025-14309 | HIGH | 7.5 | 0.4% | Dec 9, 2025 | NULL Pointer Dereference vulnerability in ravynsoft ravynos.This issue affects ravynos: through 0.5.2. |
| CVE-2025-14307 | HIGH | 8.1 | 0.3% | Dec 9, 2025 | An insecure temporary file creation vulnerability exists in the AutoExtract component of Robocode version 1.9.3.6. The c... |
| CVE-2025-14286 | HIGH | 7.5 | 0.6% | Dec 9, 2025 | A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionalit... |
| CVE-2025-13662 | HIGH | 7.8 | 0.5% | Dec 9, 2025 | Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to ... |
| CVE-2025-13661 | HIGH | 8 | 1.1% | Dec 9, 2025 | Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write ... |
| CVE-2025-13659 | HIGH | 8.8 | 1.6% | Dec 9, 2025 | Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a... |
| CVE-2025-13604 | HIGH | 7.2 | 0.3% | Dec 9, 2025 | The Login Security, FireWall, Malware removal by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scrip... |
| CVE-2025-13428 | HIGH | 7.2 | 0.3% | Dec 9, 2025 | A vulnerability exists in the SecOps SOAR server. The custom integrations feature allowed an authenticated user with an ... |
| CVE-2025-13071 | HIGH | 7.1 | 0.2% | Dec 9, 2025 | The Custom Admin Menu WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back ... |
| CVE-2025-12807 | HIGH | 8.7 | 0.4% | Dec 9, 2025 | A security issue was discovered in DataMosaix Private Cloud, allowing users with low privilege to perform sensitive data... |
| CVE-2025-12705 | HIGH | 7.2 | 0.4% | Dec 9, 2025 | The Social Reviews & Recommendations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several param... |
| CVE-2025-12381 | HIGH | 7.8 | 0.1% | Dec 9, 2025 | Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, P... |
| CVE-2025-10655 | HIGH | 8.8 | 0.5% | Dec 9, 2025 | SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled para... |
| CVE-2025-66204 | HIGH | 8.1 | 0.4% | Dec 9, 2025 | WBCE CMS is a content management system. Version 1.6.4 contains a brute-force protection bypass where an attacker can in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now