2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34291 | HIGH | 8.8 | 78.9% | Dec 5, 2025 | Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote cod... |
| CVE-2025-14111 | HIGH | 8.1 | 0.5% | Dec 5, 2025 | A security vulnerability has been detected in Rarlab RAR App up to 7.11 Build 127 on Android. This affects an unknown pa... |
| CVE-2025-14108 | HIGH | 8.8 | 9.2% | Dec 5, 2025 | A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this issue is the function zfilev2_api.O... |
| CVE-2025-14107 | HIGH | 8.8 | 10.8% | Dec 5, 2025 | A security flaw has been discovered in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this vulnerability is the function ... |
| CVE-2025-14106 | HIGH | 8.8 | 10.7% | Dec 5, 2025 | A vulnerability was identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected is the function zfilev2_api.CloseSafe of th... |
| CVE-2025-13426 | HIGH | 8.7 | 0.4% | Dec 5, 2025 | A vulnerability exists in Google Apigee's JavaCallout policy https://docs.apigee.com/api-platform/reference/policies/ja... |
| CVE-2025-66624 | HIGH | 7.5 | 0.4% | Dec 5, 2025 | BACnet Protocol Stack library provides a BACnet application layer, network layer and media access (MAC) layer communicat... |
| CVE-2025-66623 | HIGH | 7.4 | 0.2% | Dec 5, 2025 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. F... |
| CVE-2025-46603 | HIGH | 7.5 | 0.2% | Dec 5, 2025 | Dell CloudBoost Virtual Appliance, versions 19.13.0.0 and prior, contains an Improper Restriction of Excessive Authentic... |
| CVE-2025-66566 | HIGH | 8.2 | 0.5% | Dec 5, 2025 | yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor... |
| CVE-2025-66471 | HIGH | 7.5 | 0.6% | Dec 5, 2025 | urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API... |
| CVE-2025-65879 | HIGH | 8.1 | 0.7% | Dec 5, 2025 | Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability. The /goods/deleteGoods ... |
| CVE-2025-65878 | HIGH | 7.5 | 0.6% | Dec 5, 2025 | The warehouse management system version 1.2 contains an arbitrary file read vulnerability. The endpoint `/file/showImage... |
| CVE-2025-65036 | HIGH | 8.3 | 0.3% | Dec 5, 2025 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to 1.2... |
| CVE-2025-66418 | HIGH | 7.5 | 0.6% | Dec 5, 2025 | urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of li... |
| CVE-2025-65897 | HIGH | 8.8 | 0.6% | Dec 5, 2025 | zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insuf... |
| CVE-2025-65730 | HIGH | 8.8 | 0.5% | Dec 5, 2025 | Authentication Bypass via Hardcoded Credentials GoAway up to v0.62.18, fixed in 0.62.19, uses a hardcoded secret for sig... |
| CVE-2025-64053 | HIGH | 7.5 | 3.1% | Dec 5, 2025 | A Buffer overflow vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentia... |
| CVE-2025-14092 | HIGH | 7.2 | 14.7% | Dec 5, 2025 | A security vulnerability has been detected in Edimax BR-6478AC V3 1.0.15. This issue affects the function sub_416898 of ... |
| CVE-2025-14091 | HIGH | 7.3 | 0.3% | Dec 5, 2025 | A weakness has been identified in TrippWasTaken PHP-Guitar-Shop up to 6ce0868889617c1975982aae6df8e49555d0d555. This vul... |
| CVE-2025-14090 | HIGH | 7.2 | 0.3% | Dec 5, 2025 | A security flaw has been discovered in AMTT Hotel Broadband Operation System 1.0. This affects an unknown part of the fi... |
| CVE-2025-64057 | HIGH | 8.3 | 0.8% | Dec 5, 2025 | Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to sto... |
| CVE-2025-58098 | HIGH | 8.3 | 1.5% | Dec 5, 2025 | Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the ... |
| CVE-2025-14086 | HIGH | 8.8 | 0.3% | Dec 5, 2025 | A vulnerability was found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is an unknown function of the file /app-api/v1... |
| CVE-2025-14085 | HIGH | 8.8 | 0.3% | Dec 5, 2025 | A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown function of the file /app-... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now