2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58479 | HIGH | 7.5 | 0.2% | Dec 2, 2025 | Out-of-bounds read in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bo... |
| CVE-2025-58478 | HIGH | 7.5 | 0.2% | Dec 2, 2025 | Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-b... |
| CVE-2025-21080 | HIGH | 7.1 | 0.1% | Dec 2, 2025 | Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Release 1 allows local att... |
| CVE-2025-66448 | HIGH | 8.8 | 0.6% | Dec 1, 2025 | vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote co... |
| CVE-2025-66313 | HIGH | 7.2 | 0.3% | Dec 1, 2025 | ChurchCRM is an open-source church management system. In ChurchCRM 6.2.0 and earlier, there is a time-based blind SQL in... |
| CVE-2025-66304 | HIGH | 7.2 | 0.4% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section... |
| CVE-2025-66300 | HIGH | 8.5 | 0.4% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can ... |
| CVE-2025-66299 | HIGH | 8.8 | 0.5% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (S... |
| CVE-2025-66298 | HIGH | 7.5 | 0.3% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav config... |
| CVE-2025-66297 | HIGH | 8.8 | 0.7% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or e... |
| CVE-2025-66296 | HIGH | 8.8 | 0.3% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin p... |
| CVE-2025-66295 | HIGH | 8.8 | 0.5% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new use... |
| CVE-2025-66294 | HIGH | 8.8 | 2.6% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists ... |
| CVE-2025-66206 | HIGH | 8.6 | 0.3% | Dec 1, 2025 | Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, certain requests were vulnerable to path... |
| CVE-2025-65840 | HIGH | 8.8 | 0.1% | Dec 1, 2025 | PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController. |
| CVE-2025-55749 | HIGH | 7.5 | 1.4% | Dec 1, 2025 | XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is usin... |
| CVE-2025-65838 | HIGH | 7.5 | 0.4% | Dec 1, 2025 | PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method. |
| CVE-2025-63365 | HIGH | 7.1 | 0.3% | Dec 1, 2025 | SoftSea EPUB File Reader 1.0.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the EPUB file proces... |
| CVE-2025-34297 | HIGH | 8.6 | 0.1% | Dec 1, 2025 | KissFFT versions prior to the fix commit 1b083165 contain an integer overflow in kiss_fft_alloc() in kiss_fft.c on platf... |
| CVE-2025-13836 | HIGH | 7.5 | 1.5% | Dec 1, 2025 | When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content... |
| CVE-2025-7007 | HIGH | 7.5 | 0.1% | Dec 1, 2025 | NULL Pointer Dereference vulnerability in Avast Antivirus on MacOS, Avast Anitvirus on Linux when scanning a malformed W... |
| CVE-2025-8351 | HIGH | 7.8 | 0.1% | Dec 1, 2025 | Heap-based Buffer Overflow, Out-of-bounds Read vulnerability in Avira Antivirus engine when scanning a malformed file ma... |
| CVE-2025-64775 | HIGH | 7.5 | 1.4% | Dec 1, 2025 | Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. Thi... |
| CVE-2025-63535 | HIGH | 8.8 | 0.3% | Dec 1, 2025 | A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component. The applicati... |
| CVE-2025-63532 | HIGH | 8.8 | 0.3% | Dec 1, 2025 | A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component. The applic... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now