2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13677 | MEDIUM | 4.9 | 0.4% | Dec 10, 2025 | The Simple Download Counter plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2... |
| CVE-2025-67485 | MEDIUM | 5.3 | 0.2% | Dec 10, 2025 | mad-proxy is a Python-based HTTP/HTTPS proxy server for detection and blocking of malicious web activity using custom se... |
| CVE-2025-67502 | MEDIUM | 6.1 | 0.2% | Dec 10, 2025 | Taguette is an open source qualitative research tool. In versions 1.5.1 and below, attackers can craft malicious URLs t... |
| CVE-2025-64898 | MEDIUM | 5.3 | 0.4% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnera... |
| CVE-2025-64897 | MEDIUM | 5.6 | 0.1% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low... |
| CVE-2025-61823 | MEDIUM | 6.2 | 0.5% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity ... |
| CVE-2025-61822 | MEDIUM | 6.2 | 0.7% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that... |
| CVE-2025-61821 | MEDIUM | 6.8 | 0.5% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity ... |
| CVE-2025-67496 | MEDIUM | 5.4 | 0.2% | Dec 9, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below... |
| CVE-2025-67495 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | ZITADEL is an open-source identity infrastructure tool. Versions 4.0.0-rc.1 through 4.7.0 are vulnerable to DOM-Based XS... |
| CVE-2025-36437 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | IBM Planning Analytics Local 2.1.0 - 2.1.15 could disclose sensitive information about server architecture that could ai... |
| CVE-2025-34425 | MEDIUM | 6.1 | 0.4% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the WindowContext par... |
| CVE-2025-64896 | MEDIUM | 5.5 | 0.2% | Dec 9, 2025 | Creative Cloud Desktop versions 6.4.0.361 and earlier are affected by a Creation of Temporary File in Directory with Inc... |
| CVE-2025-66625 | MEDIUM | 4.9 | 0.3% | Dec 9, 2025 | Umbraco is an ASP.NET CMS. Due to unsafe handling and deletion of temporary files in versions 10.0.0 through 13.12.0, du... |
| CVE-2025-9614 | MEDIUM | 6.5 | 0.1% | Dec 9, 2025 | An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient ... |
| CVE-2025-9613 | MEDIUM | 6.5 | 0.2% | Dec 9, 2025 | A vulnerability was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insuff... |
| CVE-2025-9612 | MEDIUM | 5.1 | 0.1% | Dec 9, 2025 | An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient ... |
| CVE-2025-65572 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | Cross Site Scripting (XSS) vulnerability in AllskyTeam AllSky v2024.12.06_06 allows remote attackers to execute arbitrar... |
| CVE-2025-65300 | MEDIUM | 5.4 | 0.2% | Dec 9, 2025 | A stored Cross-Site Scripting (XSS) vulnerability exists in the Coohom SaaS Platform feVersion=1760060603897 (2025-10-28... |
| CVE-2025-64894 | MEDIUM | 5.5 | 0.1% | Dec 9, 2025 | DNG SDK versions 1.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead to ap... |
| CVE-2025-64670 | MEDIUM | 6.5 | 0.9% | Dec 9, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker... |
| CVE-2025-64667 | MEDIUM | 5.3 | 0.8% | Dec 9, 2025 | User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attack... |
| CVE-2025-62631 | MEDIUM | 5.6 | 0.3% | Dec 9, 2025 | An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all vers... |
| CVE-2025-62570 | MEDIUM | 5.5 | 0.4% | Dec 9, 2025 | Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information loc... |
| CVE-2025-62567 | MEDIUM | 5.3 | 0.9% | Dec 9, 2025 | Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now