2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11838 | HIGH | 7.5 | 0.5% | Dec 4, 2025 | A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of... |
| CVE-2025-10285 | HIGH | 7.4 | 0.2% | Dec 4, 2025 | The web interface of the Silicon Labs Simplicity Device Manager is exposed publicly and can be used to extract the NTLMv... |
| CVE-2025-66575 | HIGH | 7.8 | 0.4% | Dec 4, 2025 | VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute... |
| CVE-2025-66573 | HIGH | 7.5 | 0.3% | Dec 4, 2025 | Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive info... |
| CVE-2025-66555 | HIGH | 8.8 | 0.5% | Dec 4, 2025 | AirKeyboard iOS App 1.0.5 contains a missing authentication vulnerability that allows unauthenticated attackers to type ... |
| CVE-2025-66237 | HIGH | 8.4 | 0.1% | Dec 4, 2025 | DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to... |
| CVE-2025-63896 | HIGH | 7.6 | 0.3% | Dec 4, 2025 | An issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows ... |
| CVE-2025-55948 | HIGH | 7.3 | 0.2% | Dec 4, 2025 | This vulnerability fundamentally arises from yzcheng90 X-SpringBoot 6.0's implementation of role-based access control (R... |
| CVE-2025-27935 | HIGH | 8.6 | 0.4% | Dec 4, 2025 | The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The serv... |
| CVE-2025-13543 | HIGH | 8.8 | 0.7% | Dec 4, 2025 | The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in th... |
| CVE-2025-65958 | HIGH | 7.1 | 4.0% | Dec 4, 2025 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Se... |
| CVE-2025-65883 | HIGH | 8.4 | 0.3% | Dec 4, 2025 | A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local networ... |
| CVE-2025-12097 | HIGH | 8.7 | 0.5% | Dec 4, 2025 | There is a relative path traversal vulnerability in the NI System Web Server that may result in information disclosure. ... |
| CVE-2025-65945 | HIGH | 7.5 | 0.2% | Dec 4, 2025 | auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth... |
| CVE-2025-65637 | HIGH | 7.5 | 0.6% | Dec 4, 2025 | A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line pa... |
| CVE-2025-14016 | HIGH | 8.1 | 0.2% | Dec 4, 2025 | A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the ... |
| CVE-2025-63363 | HIGH | 7.5 | 0.3% | Dec 4, 2025 | A lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V... |
| CVE-2025-14012 | HIGH | 7.2 | 0.3% | Dec 4, 2025 | A vulnerability was determined in JIZHICMS up to 2.5.5. The affected element is the function deleteAll/findAll/delete of... |
| CVE-2025-14011 | HIGH | 7.2 | 0.3% | Dec 4, 2025 | A vulnerability was found in JIZHICMS up to 2.5.5. Impacted is the function commentlist of the file /index.php/admins/Co... |
| CVE-2025-66287 | HIGH | 8.8 | 0.4% | Dec 4, 2025 | A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper me... |
| CVE-2025-63364 | HIGH | 7.5 | 0.2% | Dec 4, 2025 | Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.00... |
| CVE-2025-57213 | HIGH | 7.5 | 0.2% | Dec 4, 2025 | Incorrect access control in the component orderService.queryObject of platform v1.0.0 allows attackers to access sensiti... |
| CVE-2025-57212 | HIGH | 7.5 | 0.2% | Dec 4, 2025 | Incorrect access control in the component ApiOrderService.java of platform v1.0.0 allows attackers to access sensitive i... |
| CVE-2025-57210 | HIGH | 7.5 | 0.2% | Dec 4, 2025 | Incorrect access control in the component ApiPayController.java of platform v1.0.0 allows attackers to access sensitive ... |
| CVE-2025-56427 | HIGH | 7.5 | 0.8% | Dec 4, 2025 | Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via th... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now