2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12744 | HIGH | 8.8 | 0.6% | Dec 3, 2025 | A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from a... |
| CVE-2025-13645 | HIGH | 7.2 | 0.9% | Dec 3, 2025 | The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val... |
| CVE-2025-66476 | HIGH | 7.8 | 0.4% | Dec 2, 2025 | Vim is an open source, command line text editor. Prior to version 9.1.1947, an uncontrolled search path vulnerability on... |
| CVE-2025-64778 | HIGH | 7.8 | 0.1% | Dec 2, 2025 | NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. The... |
| CVE-2025-64642 | HIGH | 7.8 | 0.1% | Dec 2, 2025 | NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which... |
| CVE-2025-64298 | HIGH | 7.5 | 0.2% | Dec 2, 2025 | NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are expose... |
| CVE-2025-62575 | HIGH | 8.8 | 0.4% | Dec 2, 2025 | NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and o... |
| CVE-2025-61940 | HIGH | 8.8 | 0.3% | Dec 2, 2025 | NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User ... |
| CVE-2025-65877 | HIGH | 7.5 | 0.3% | Dec 2, 2025 | Lvzhou CMS before commit c4ea0eb9cab5f6739b2c87e77d9ef304017ed615 (2025-09-22) is vulnerable to SQL injection via the 't... |
| CVE-2025-66416 | HIGH | 8.1 | 0.4% | Dec 2, 2025 | The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to versi... |
| CVE-2025-66414 | HIGH | 8.1 | 0.4% | Dec 2, 2025 | MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The M... |
| CVE-2025-61729 | HIGH | 7.5 | 0.5% | Dec 2, 2025 | Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be p... |
| CVE-2025-34352 | HIGH | 8.5 | 0.2% | Dec 2, 2025 | JumpCloud Remote Assist for Windows versions prior to 0.317.0 include an uninstaller that is invoked by the JumpCloud Wi... |
| CVE-2025-13721 | HIGH | 7.5 | 0.2% | Dec 2, 2025 | Race in v8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via ... |
| CVE-2025-13720 | HIGH | 8.8 | 0.2% | Dec 2, 2025 | Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer pr... |
| CVE-2025-13639 | HIGH | 8.1 | 0.2% | Dec 2, 2025 | Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbi... |
| CVE-2025-13638 | HIGH | 8.8 | 0.2% | Dec 2, 2025 | Use after free in Media Stream in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit ... |
| CVE-2025-13633 | HIGH | 8.8 | 0.4% | Dec 2, 2025 | Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromi... |
| CVE-2025-13631 | HIGH | 8.8 | 0.3% | Dec 2, 2025 | Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowed a remote attacker ... |
| CVE-2025-13630 | HIGH | 8.8 | 0.4% | Dec 2, 2025 | Type Confusion in V8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2025-66399 | HIGH | 8.8 | 10.8% | Dec 2, 2025 | Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw i... |
| CVE-2025-65844 | HIGH | 7.5 | 0.3% | Dec 2, 2025 | EverShop 2.0.1 allows a remote unauthenticated attacker to upload arbitrary files and create directories via the /api/im... |
| CVE-2025-13827 | HIGH | 8.8 | 0.4% | Dec 2, 2025 | Summary Arbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not res... |
| CVE-2025-64460 | HIGH | 7.5 | 2.1% | Dec 2, 2025 | An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. Algorithmic complexity in `django... |
| CVE-2025-59702 | HIGH | 7.2 | 0.3% | Dec 2, 2025 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now