2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62173 | HIGH | 8.6 | 0.2% | Dec 4, 2025 | ## Summary Authenticated SQL Injection Vulnerability in Endpoint Module Rest API |
| CVE-2025-66404 | HIGH | 8.8 | 1.3% | Dec 3, 2025 | MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is ... |
| CVE-2025-66293 | HIGH | 7.1 | 0.3% | Dec 3, 2025 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2025-65868 | HIGH | 7.5 | 0.4% | Dec 3, 2025 | XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted b... |
| CVE-2025-66453 | HIGH | 7.5 | 0.2% | Dec 3, 2025 | Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, w... |
| CVE-2025-65027 | HIGH | 7.6 | 0.3% | Dec 3, 2025 | RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive inte... |
| CVE-2025-13086 | HIGH | 7.5 | 0.6% | Dec 3, 2025 | Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows... |
| CVE-2025-12385 | HIGH | 8.7 | 0.3% | Dec 3, 2025 | Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability i... |
| CVE-2025-66220 | HIGH | 7.1 | 0.2% | Dec 3, 2025 | Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy’s mTLS ce... |
| CVE-2025-50360 | HIGH | 8.4 | 0.2% | Dec 3, 2025 | A heap buffer overflow in compiler.c and compiler.h in Pepper language 0.1.1commit 961a5d9988c5986d563310275adad3fd181b2... |
| CVE-2025-33211 | HIGH | 7.5 | 0.6% | Dec 3, 2025 | NVIDIA Triton Server for Linux contains a vulnerability where an attacker may cause an improper validation of specified ... |
| CVE-2025-33208 | HIGH | 8.8 | 0.4% | Dec 3, 2025 | NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path.... |
| CVE-2025-33201 | HIGH | 7.5 | 0.8% | Dec 3, 2025 | NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause an improper check for unusual or exc... |
| CVE-2025-12819 | HIGH | 8.1 | 0.3% | Dec 3, 2025 | Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to ... |
| CVE-2025-66431 | HIGH | 7.8 | 0.2% | Dec 3, 2025 | WebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remote authenticated users to execute arbitr... |
| CVE-2025-65843 | HIGH | 7.7 | 0.2% | Dec 3, 2025 | Aquarius Desktop 3.0.069 for macOS contains an insecure file handling vulnerability in its support data archive generati... |
| CVE-2025-54326 | HIGH | 7.5 | 0.3% | Dec 3, 2025 | An issue was discovered in Camera in Samsung Mobile Processor Exynos 1280 and 2200. Unnecessary registration of a hardwa... |
| CVE-2025-54065 | HIGH | 7.9 | 0.1% | Dec 3, 2025 | GZDoom is a feature centric port for all Doom engine games. GZDoom is an open source Doom engine. In versions 4.14.2 and... |
| CVE-2025-13492 | HIGH | 7 | 0.1% | Dec 3, 2025 | A potential security vulnerability has been identified in HP Image Assistant for versions prior to 5.3.3. The vulnerabil... |
| CVE-2025-65320 | HIGH | 7.5 | 0.2% | Dec 3, 2025 | Abacre Restaurant Point of Sale (POS) up to 15.0.0.1656 are vulnerable to Cleartext Storage of Sensitive Information in ... |
| CVE-2025-57201 | HIGH | 8.8 | 12.8% | Dec 3, 2025 | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec... |
| CVE-2025-57199 | HIGH | 8.8 | 2.6% | Dec 3, 2025 | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec... |
| CVE-2025-57198 | HIGH | 8.8 | 2.1% | Dec 3, 2025 | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec... |
| CVE-2025-53841 | HIGH | 7.8 | 0.1% | Dec 3, 2025 | The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.... |
| CVE-2025-13947 | HIGH | 7.4 | 0.3% | Dec 3, 2025 | A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal an... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now