2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64541 | MEDIUM | 5.4 | 0.2% | Dec 10, 2025 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-56429 | MEDIUM | 6.1 | 0.2% | Dec 10, 2025 | Cross Site Scripting vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to obtain sens... |
| CVE-2025-34430 | MEDIUM | 4.3 | 0.2% | Dec 10, 2025 | 1Panel versions 1.10.33 through 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the panel name manag... |
| CVE-2025-65754 | MEDIUM | 6.1 | 0.4% | Dec 10, 2025 | Cross Site Scripting vulnerability in Algernon v1.17.4 allows attackers to execute arbitrary code via injecting a crafte... |
| CVE-2025-67643 | MEDIUM | 4.3 | 0.3% | Dec 10, 2025 | Jenkins Redpen - Pipeline Reporter for Jira Plugin 1.054.v7b_9517b_6b_202 and earlier does not correctly perform path va... |
| CVE-2025-67642 | MEDIUM | 4.3 | 0.2% | Dec 10, 2025 | Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credential... |
| CVE-2025-67641 | MEDIUM | 5.4 | 0.3% | Dec 10, 2025 | Jenkins Coverage Plugin 2.3054.ve1ff7b_a_a_123b_ and earlier does not validate the configured coverage results ID when c... |
| CVE-2025-67640 | MEDIUM | 5 | 0.2% | Dec 10, 2025 | Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of... |
| CVE-2025-67638 | MEDIUM | 4.3 | 0.1% | Dec 10, 2025 | Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configu... |
| CVE-2025-67637 | MEDIUM | 4.3 | 0.2% | Dec 10, 2025 | Jenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files... |
| CVE-2025-67636 | MEDIUM | 4.3 | 0.2% | Dec 10, 2025 | A missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permiss... |
| CVE-2025-65815 | MEDIUM | 6.5 | 0.5% | Dec 10, 2025 | A lack of security checks in the file import process of AB TECHNOLOGY Document Reader: PDF, DOC, PPT v65.0 allows attack... |
| CVE-2025-65814 | MEDIUM | 6.5 | 0.5% | Dec 10, 2025 | A lack of security checks in the file import process of RHOPHI Analytics LLP Office App-Edit Word v6.4.1 allows attacker... |
| CVE-2025-52493 | MEDIUM | 6.5 | 0.3% | Dec 10, 2025 | PagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Altho... |
| CVE-2025-65803 | MEDIUM | 6.5 | 0.2% | Dec 10, 2025 | An integer overflow in the psdParser::ReadImageData function of FreeImage v3.18.0 and before allows attackers to cause a... |
| CVE-2025-13125 | MEDIUM | 4.3 | 0.2% | Dec 10, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Im Park Information Technology, Electronics, Press, Pu... |
| CVE-2025-9315 | MEDIUM | 6.3 | 0.4% | Dec 10, 2025 | An unauthenticated device registration vulnerability, caused by Improperly Controlled Modification of Dynamically-Determ... |
| CVE-2025-66004 | MEDIUM | 5.7 | 0.1% | Dec 10, 2025 | A Path Traversal vulnerability in usbmuxd allows local users to escalate to the service user.This issue affects usbmuxd:... |
| CVE-2025-9056 | MEDIUM | 5.3 | 0.2% | Dec 10, 2025 | Unprotected service in the AudioLink component allows a local attacker to overwrite system files via unauthorized servic... |
| CVE-2025-13677 | MEDIUM | 4.9 | 0.4% | Dec 10, 2025 | The Simple Download Counter plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2... |
| CVE-2025-67485 | MEDIUM | 5.3 | 0.2% | Dec 10, 2025 | mad-proxy is a Python-based HTTP/HTTPS proxy server for detection and blocking of malicious web activity using custom se... |
| CVE-2025-67502 | MEDIUM | 6.1 | 0.2% | Dec 10, 2025 | Taguette is an open source qualitative research tool. In versions 1.5.1 and below, attackers can craft malicious URLs t... |
| CVE-2025-64898 | MEDIUM | 5.3 | 0.4% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnera... |
| CVE-2025-64897 | MEDIUM | 5.6 | 0.1% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low... |
| CVE-2025-61823 | MEDIUM | 6.2 | 0.4% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now