2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13654 | HIGH | 7.5 | 0.8% | Dec 5, 2025 | A stack buffer overflow vulnerability exists in the buffer_get function of duc, a disk management tool, where a conditio... |
| CVE-2025-59775 | HIGH | 7.5 | 0.8% | Dec 5, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server on Windows with AllowEncodedSlashes On and M... |
| CVE-2025-55753 | HIGH | 7.5 | 0.4% | Dec 5, 2025 | An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in defaul... |
| CVE-2025-13614 | HIGH | 8.1 | 0.3% | Dec 5, 2025 | The Cool Tag Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cool_tag_cloud' s... |
| CVE-2025-12879 | HIGH | 8.8 | 0.2% | Dec 5, 2025 | The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and i... |
| CVE-2025-12851 | HIGH | 8.1 | 0.7% | Dec 5, 2025 | The My auctions allegro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including,... |
| CVE-2025-12850 | HIGH | 7.5 | 0.3% | Dec 5, 2025 | The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versio... |
| CVE-2025-12189 | HIGH | 8.8 | 0.3% | Dec 5, 2025 | The Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents plugin for WordPres... |
| CVE-2025-12181 | HIGH | 8.8 | 0.5% | Dec 5, 2025 | The ContentStudio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th... |
| CVE-2025-12154 | HIGH | 8.8 | 0.4% | Dec 5, 2025 | The Auto Thumbnailer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in... |
| CVE-2025-12153 | HIGH | 8.8 | 0.5% | Dec 5, 2025 | The Featured Image via URL plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat... |
| CVE-2025-13066 | HIGH | 8.8 | 0.5% | Dec 5, 2025 | The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including,... |
| CVE-2025-66564 | HIGH | 7.5 | 0.4% | Dec 4, 2025 | Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest... |
| CVE-2025-66559 | HIGH | 8 | 0.3% | Dec 4, 2025 | Taiko Alethia is an Ethereum-equivalent, permissionless, based rollup designed to scale Ethereum without compromising it... |
| CVE-2025-14051 | HIGH | 8.8 | 0.4% | Dec 4, 2025 | A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddres... |
| CVE-2025-13373 | HIGH | 8.7 | 0.4% | Dec 4, 2025 | Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could al... |
| CVE-2025-66506 | HIGH | 7.5 | 0.2% | Dec 4, 2025 | Fulcio is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identit... |
| CVE-2025-66238 | HIGH | 7.4 | 0.3% | Dec 4, 2025 | DCIM dcTrack allows an attacker to misuse certain remote access features. An authenticated user with access to the appli... |
| CVE-2025-53704 | HIGH | 8.7 | 0.2% | Dec 4, 2025 | The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the acc... |
| CVE-2025-1547 | HIGH | 7.2 | 0.3% | Dec 4, 2025 | A stack-based buffer overflow vulnerability [CWE-121] in WatchGuard Fireware OS's certificate request command could allo... |
| CVE-2025-1545 | HIGH | 7.5 | 0.5% | Dec 4, 2025 | An XPath Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensi... |
| CVE-2025-13932 | HIGH | 8.3 | 0.2% | Dec 4, 2025 | The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Reference ... |
| CVE-2025-12196 | HIGH | 7.2 | 0.6% | Dec 4, 2025 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to exe... |
| CVE-2025-12195 | HIGH | 7.2 | 0.6% | Dec 4, 2025 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to exe... |
| CVE-2025-12026 | HIGH | 7.2 | 0.4% | Dec 4, 2025 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could allow an authenticate... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now