2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54065 | HIGH | 7.9 | 0.1% | Dec 3, 2025 | GZDoom is a feature centric port for all Doom engine games. GZDoom is an open source Doom engine. In versions 4.14.2 and... |
| CVE-2025-13492 | HIGH | 7 | 0.1% | Dec 3, 2025 | A potential security vulnerability has been identified in HP Image Assistant for versions prior to 5.3.3. The vulnerabil... |
| CVE-2025-65320 | HIGH | 7.5 | 0.2% | Dec 3, 2025 | Abacre Restaurant Point of Sale (POS) up to 15.0.0.1656 are vulnerable to Cleartext Storage of Sensitive Information in ... |
| CVE-2025-57201 | HIGH | 8.8 | 12.8% | Dec 3, 2025 | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec... |
| CVE-2025-57199 | HIGH | 8.8 | 2.6% | Dec 3, 2025 | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec... |
| CVE-2025-57198 | HIGH | 8.8 | 2.1% | Dec 3, 2025 | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec... |
| CVE-2025-53841 | HIGH | 7.8 | 0.1% | Dec 3, 2025 | The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.... |
| CVE-2025-13947 | HIGH | 7.4 | 0.3% | Dec 3, 2025 | A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal an... |
| CVE-2025-12744 | HIGH | 8.8 | 0.6% | Dec 3, 2025 | A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from a... |
| CVE-2025-13645 | HIGH | 7.2 | 0.9% | Dec 3, 2025 | The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val... |
| CVE-2025-66476 | HIGH | 7.8 | 0.4% | Dec 2, 2025 | Vim is an open source, command line text editor. Prior to version 9.1.1947, an uncontrolled search path vulnerability on... |
| CVE-2025-64778 | HIGH | 7.8 | 0.1% | Dec 2, 2025 | NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. The... |
| CVE-2025-64642 | HIGH | 7.8 | 0.1% | Dec 2, 2025 | NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which... |
| CVE-2025-64298 | HIGH | 7.5 | 0.2% | Dec 2, 2025 | NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are expose... |
| CVE-2025-62575 | HIGH | 8.8 | 0.4% | Dec 2, 2025 | NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and o... |
| CVE-2025-61940 | HIGH | 8.8 | 0.3% | Dec 2, 2025 | NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User ... |
| CVE-2025-65877 | HIGH | 7.5 | 0.3% | Dec 2, 2025 | Lvzhou CMS before commit c4ea0eb9cab5f6739b2c87e77d9ef304017ed615 (2025-09-22) is vulnerable to SQL injection via the 't... |
| CVE-2025-66416 | HIGH | 8.1 | 0.4% | Dec 2, 2025 | The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to versi... |
| CVE-2025-66414 | HIGH | 8.1 | 0.4% | Dec 2, 2025 | MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The M... |
| CVE-2025-61729 | HIGH | 7.5 | 0.5% | Dec 2, 2025 | Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be p... |
| CVE-2025-34352 | HIGH | 8.5 | 0.2% | Dec 2, 2025 | JumpCloud Remote Assist for Windows versions prior to 0.317.0 include an uninstaller that is invoked by the JumpCloud Wi... |
| CVE-2025-13721 | HIGH | 7.5 | 0.2% | Dec 2, 2025 | Race in v8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via ... |
| CVE-2025-13720 | HIGH | 8.8 | 0.3% | Dec 2, 2025 | Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer pr... |
| CVE-2025-13639 | HIGH | 8.1 | 0.3% | Dec 2, 2025 | Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbi... |
| CVE-2025-13638 | HIGH | 8.8 | 0.3% | Dec 2, 2025 | Use after free in Media Stream in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now