2025 CVE Vulnerabilities
45,143 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14013 | MEDIUM | 4.8 | 0.2% | Dec 4, 2025 | A vulnerability was identified in JIZHICMS up to 2.5.5. The impacted element is an unknown function of the file /index.p... |
| CVE-2025-13488 | MEDIUM | 5.1 | 0.3% | Dec 4, 2025 | Due to a regression introduced in version 3.83.0, a security header is no longer applied to certain user-uploaded conten... |
| CVE-2025-9127 | MEDIUM | 5.5 | 0.1% | Dec 4, 2025 | A vulnerability exists in PX Enterprise whereby sensitive information may be logged under specific conditions. |
| CVE-2025-66373 | MEDIUM | 4.8 | 0.2% | Dec 4, 2025 | Akamai Ghost on Akamai CDN edge servers before 2025-11-17 has a chunked request body processing error that can result in... |
| CVE-2025-8074 | MEDIUM | 5.6 | 0.1% | Dec 4, 2025 | Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users... |
| CVE-2025-65516 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | A stored cross-site scripting (XSS) vulnerability was discovered in Seafile Community Edition prior to version 13.0.12. ... |
| CVE-2025-63681 | MEDIUM | 4.3 | 0.3% | Dec 4, 2025 | open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tas... |
| CVE-2025-61148 | MEDIUM | 6.5 | 0.3% | Dec 4, 2025 | An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authentic... |
| CVE-2025-40251 | MEDIUM | 5.5 | 0.1% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: devlink: rate: Unset parent pointer in devl_rate_no... |
| CVE-2025-2848 | MEDIUM | 6.3 | 0.4% | Dec 4, 2025 | A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, ... |
| CVE-2025-29845 | MEDIUM | 4.3 | 0.4% | Dec 4, 2025 | A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files. |
| CVE-2025-29844 | MEDIUM | 4.3 | 0.4% | Dec 4, 2025 | A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information. |
| CVE-2025-29843 | MEDIUM | 5.4 | 0.3% | Dec 4, 2025 | A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files. |
| CVE-2025-14007 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | A vulnerability was detected in dayrui XunRuiCMS up to 4.7.1. This affects an unknown part of the file /admin79f2ec220c7... |
| CVE-2025-14006 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | A security vulnerability has been detected in dayrui XunRuiCMS up to 4.7.1. Affected by this issue is some unknown funct... |
| CVE-2025-14005 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | A weakness has been identified in dayrui XunRuiCMS up to 4.7.1. Affected by this vulnerability is an unknown functionali... |
| CVE-2025-11222 | MEDIUM | 6.1 | 0.1% | Dec 4, 2025 | Central Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to u... |
| CVE-2025-41080 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attac... |
| CVE-2025-41079 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attac... |
| CVE-2025-14010 | MEDIUM | 5.5 | 0.1% | Dec 4, 2025 | A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sen... |
| CVE-2025-12826 | MEDIUM | 4.8 | 0.3% | Dec 4, 2025 | The Custom Post Type UI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,... |
| CVE-2025-12782 | MEDIUM | 4.3 | 0.2% | Dec 4, 2025 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions u... |
| CVE-2025-13513 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | The Clik stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` param... |
| CVE-2025-11379 | MEDIUM | 5.3 | 0.3% | Dec 4, 2025 | The WebP Express plugin for WordPress is vulnerable to information exposure via config files in all versions up to, and ... |
| CVE-2025-66411 | MEDIUM | 5.5 | 0.2% | Dec 3, 2025 | Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now