2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66506 | HIGH | 7.5 | 0.2% | Dec 4, 2025 | Fulcio is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identit... |
| CVE-2025-66238 | HIGH | 7.4 | 0.3% | Dec 4, 2025 | DCIM dcTrack allows an attacker to misuse certain remote access features. An authenticated user with access to the appli... |
| CVE-2025-53704 | HIGH | 8.7 | 0.2% | Dec 4, 2025 | The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the acc... |
| CVE-2025-1547 | HIGH | 7.2 | 0.4% | Dec 4, 2025 | A stack-based buffer overflow vulnerability [CWE-121] in WatchGuard Fireware OS's certificate request command could allo... |
| CVE-2025-1545 | HIGH | 7.5 | 0.5% | Dec 4, 2025 | An XPath Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensi... |
| CVE-2025-13932 | HIGH | 8.3 | 0.2% | Dec 4, 2025 | The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Reference ... |
| CVE-2025-12196 | HIGH | 7.2 | 0.6% | Dec 4, 2025 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to exe... |
| CVE-2025-12195 | HIGH | 7.2 | 0.6% | Dec 4, 2025 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to exe... |
| CVE-2025-12026 | HIGH | 7.2 | 0.4% | Dec 4, 2025 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could allow an authenticate... |
| CVE-2025-11838 | HIGH | 7.5 | 0.5% | Dec 4, 2025 | A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of... |
| CVE-2025-10285 | HIGH | 7.4 | 0.2% | Dec 4, 2025 | The web interface of the Silicon Labs Simplicity Device Manager is exposed publicly and can be used to extract the NTLMv... |
| CVE-2025-66575 | HIGH | 7.8 | 0.5% | Dec 4, 2025 | VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute... |
| CVE-2025-66573 | HIGH | 7.5 | 0.3% | Dec 4, 2025 | Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive info... |
| CVE-2025-66555 | HIGH | 8.8 | 0.5% | Dec 4, 2025 | AirKeyboard iOS App 1.0.5 contains a missing authentication vulnerability that allows unauthenticated attackers to type ... |
| CVE-2025-63896 | HIGH | 7.6 | 0.3% | Dec 4, 2025 | An issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows ... |
| CVE-2025-55948 | HIGH | 7.3 | 0.2% | Dec 4, 2025 | This vulnerability fundamentally arises from yzcheng90 X-SpringBoot 6.0's implementation of role-based access control (R... |
| CVE-2025-27935 | HIGH | 8.6 | 0.4% | Dec 4, 2025 | The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The serv... |
| CVE-2025-13543 | HIGH | 8.8 | 0.7% | Dec 4, 2025 | The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in th... |
| CVE-2025-65958 | HIGH | 7.1 | 4.0% | Dec 4, 2025 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Se... |
| CVE-2025-65883 | HIGH | 8.4 | 0.3% | Dec 4, 2025 | A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local networ... |
| CVE-2025-12097 | HIGH | 8.7 | 0.5% | Dec 4, 2025 | There is a relative path traversal vulnerability in the NI System Web Server that may result in information disclosure. ... |
| CVE-2025-65945 | HIGH | 7.5 | 0.2% | Dec 4, 2025 | auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth... |
| CVE-2025-65637 | HIGH | 7.5 | 0.6% | Dec 4, 2025 | A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line pa... |
| CVE-2025-14016 | HIGH | 8.1 | 0.2% | Dec 4, 2025 | A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the ... |
| CVE-2025-63363 | HIGH | 7.5 | 0.3% | Dec 4, 2025 | A lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now