2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61822 | MEDIUM | 6.2 | 0.6% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that... |
| CVE-2025-61821 | MEDIUM | 6.8 | 0.5% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity ... |
| CVE-2025-67496 | MEDIUM | 5.4 | 0.2% | Dec 9, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below... |
| CVE-2025-67495 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | ZITADEL is an open-source identity infrastructure tool. Versions 4.0.0-rc.1 through 4.7.0 are vulnerable to DOM-Based XS... |
| CVE-2025-36437 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | IBM Planning Analytics Local 2.1.0 - 2.1.15 could disclose sensitive information about server architecture that could ai... |
| CVE-2025-34425 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the WindowContext par... |
| CVE-2025-64896 | MEDIUM | 5.5 | 0.2% | Dec 9, 2025 | Creative Cloud Desktop versions 6.4.0.361 and earlier are affected by a Creation of Temporary File in Directory with Inc... |
| CVE-2025-66625 | MEDIUM | 4.9 | 0.3% | Dec 9, 2025 | Umbraco is an ASP.NET CMS. Due to unsafe handling and deletion of temporary files in versions 10.0.0 through 13.12.0, du... |
| CVE-2025-9614 | MEDIUM | 6.5 | 0.1% | Dec 9, 2025 | An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient ... |
| CVE-2025-9613 | MEDIUM | 6.5 | 0.2% | Dec 9, 2025 | A vulnerability was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insuff... |
| CVE-2025-9612 | MEDIUM | 5.1 | 0.1% | Dec 9, 2025 | An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient ... |
| CVE-2025-65572 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | Cross Site Scripting (XSS) vulnerability in AllskyTeam AllSky v2024.12.06_06 allows remote attackers to execute arbitrar... |
| CVE-2025-65300 | MEDIUM | 5.4 | 0.2% | Dec 9, 2025 | A stored Cross-Site Scripting (XSS) vulnerability exists in the Coohom SaaS Platform feVersion=1760060603897 (2025-10-28... |
| CVE-2025-64894 | MEDIUM | 5.5 | 0.1% | Dec 9, 2025 | DNG SDK versions 1.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead to ap... |
| CVE-2025-64670 | MEDIUM | 6.5 | 0.9% | Dec 9, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker... |
| CVE-2025-64667 | MEDIUM | 5.3 | 0.8% | Dec 9, 2025 | User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attack... |
| CVE-2025-62631 | MEDIUM | 5.6 | 0.3% | Dec 9, 2025 | An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all vers... |
| CVE-2025-62570 | MEDIUM | 5.5 | 0.4% | Dec 9, 2025 | Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information loc... |
| CVE-2025-62567 | MEDIUM | 5.3 | 0.9% | Dec 9, 2025 | Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network. |
| CVE-2025-62473 | MEDIUM | 6.5 | 1.0% | Dec 9, 2025 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa... |
| CVE-2025-62468 | MEDIUM | 5.5 | 0.5% | Dec 9, 2025 | Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally. |
| CVE-2025-62465 | MEDIUM | 6.5 | 0.4% | Dec 9, 2025 | Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally. |
| CVE-2025-62463 | MEDIUM | 6.5 | 0.4% | Dec 9, 2025 | Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally. |
| CVE-2025-61078 | MEDIUM | 6.1 | 0.2% | Dec 9, 2025 | Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrar... |
| CVE-2025-59810 | MEDIUM | 6.5 | 0.2% | Dec 9, 2025 | An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now