2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63365 | HIGH | 7.1 | 0.3% | Dec 1, 2025 | SoftSea EPUB File Reader 1.0.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the EPUB file proces... |
| CVE-2025-34297 | HIGH | 8.6 | 0.1% | Dec 1, 2025 | KissFFT versions prior to the fix commit 1b083165 contain an integer overflow in kiss_fft_alloc() in kiss_fft.c on platf... |
| CVE-2025-13836 | HIGH | 7.5 | 1.6% | Dec 1, 2025 | When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content... |
| CVE-2025-7007 | HIGH | 7.5 | 0.1% | Dec 1, 2025 | NULL Pointer Dereference vulnerability in Avast Antivirus on MacOS, Avast Anitvirus on Linux when scanning a malformed W... |
| CVE-2025-8351 | HIGH | 7.8 | 0.1% | Dec 1, 2025 | Heap-based Buffer Overflow, Out-of-bounds Read vulnerability in Avira Antivirus engine when scanning a malformed file ma... |
| CVE-2025-64775 | HIGH | 7.5 | 1.4% | Dec 1, 2025 | Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. Thi... |
| CVE-2025-63535 | HIGH | 8.8 | 0.3% | Dec 1, 2025 | A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component. The applicati... |
| CVE-2025-63532 | HIGH | 8.8 | 0.3% | Dec 1, 2025 | A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component. The applic... |
| CVE-2025-61229 | HIGH | 7.8 | 0.1% | Dec 1, 2025 | An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to ex... |
| CVE-2025-61228 | HIGH | 7.8 | 0.1% | Dec 1, 2025 | An issue in Shirt Pocket SuperDuper! V.3.10 and before allows a local attacker to execute arbitrary code via the softwar... |
| CVE-2025-57489 | HIGH | 8.1 | 0.3% | Dec 1, 2025 | Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privile... |
| CVE-2025-55222 | HIGH | 7.5 | 0.4% | Dec 1, 2025 | A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec... |
| CVE-2025-55221 | HIGH | 7.5 | 0.4% | Dec 1, 2025 | A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec... |
| CVE-2025-54851 | HIGH | 7.5 | 0.4% | Dec 1, 2025 | A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiwa... |
| CVE-2025-54850 | HIGH | 7.5 | 0.3% | Dec 1, 2025 | A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiwa... |
| CVE-2025-54849 | HIGH | 7.5 | 0.3% | Dec 1, 2025 | A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiwa... |
| CVE-2025-54848 | HIGH | 7.5 | 0.4% | Dec 1, 2025 | A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiwa... |
| CVE-2025-26858 | HIGH | 7.5 | 0.6% | Dec 1, 2025 | A buffer overflow vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially... |
| CVE-2025-23417 | HIGH | 7.5 | 0.5% | Dec 1, 2025 | A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. ... |
| CVE-2025-13829 | HIGH | 8.6 | 0.3% | Dec 1, 2025 | Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private... |
| CVE-2025-11699 | HIGH | 7.1 | 0.4% | Dec 1, 2025 | nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination... |
| CVE-2025-10101 | HIGH | 7.8 | 0.2% | Dec 1, 2025 | Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Mach-O file may allow Local Ex... |
| CVE-2025-63529 | HIGH | 8.8 | 0.3% | Dec 1, 2025 | A session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set ... |
| CVE-2025-63525 | HIGH | 8.8 | 0.4% | Dec 1, 2025 | An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with esc... |
| CVE-2025-59789 | HIGH | 7.5 | 1.5% | Dec 1, 2025 | Uncontrolled recursion in the json2pb component in Apache bRPC (version < 1.15.0) on all platforms allows remote attacke... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now