2025 CVE Vulnerabilities
45,143 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66406 | MEDIUM | 5 | 0.1% | Dec 3, 2025 | Step CA is an online certificate authority for secure, automated certificate management for DevOps. Prior to 0.29.0, the... |
| CVE-2025-65345 | MEDIUM | 6.5 | 0.5% | Dec 3, 2025 | alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality all... |
| CVE-2025-65097 | MEDIUM | 6.5 | 0.2% | Dec 3, 2025 | RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive inte... |
| CVE-2025-65096 | MEDIUM | 4.3 | 0.2% | Dec 3, 2025 | RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive inte... |
| CVE-2025-61727 | MEDIUM | 6.5 | 0.3% | Dec 3, 2025 | An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certifi... |
| CVE-2025-50361 | MEDIUM | 5.1 | 0.2% | Dec 3, 2025 | Buffer Overflow was found in SmallBASIC community SmallBASIC with SDL Before v12_28, and commit sha:298a1d495355959db364... |
| CVE-2025-63402 | MEDIUM | 5.5 | 0.3% | Dec 3, 2025 | An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code vi... |
| CVE-2025-63401 | MEDIUM | 5.5 | 0.3% | Dec 3, 2025 | Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to... |
| CVE-2025-13992 | MEDIUM | 4.7 | 0.2% | Dec 3, 2025 | Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote atta... |
| CVE-2025-12084 | MEDIUM | 5.3 | 0.7% | Dec 3, 2025 | When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_ca... |
| CVE-2025-64763 | MEDIUM | 5.3 | 0.3% | Dec 3, 2025 | Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, when Envoy is c... |
| CVE-2025-64527 | MEDIUM | 6.5 | 0.5% | Dec 3, 2025 | Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy crashes w... |
| CVE-2025-65842 | MEDIUM | 5.1 | 0.1% | Dec 3, 2025 | The Aquarius HelperTool (1.0.003) privileged XPC service on macOS contains multiple flaws that allow local privilege esc... |
| CVE-2025-65841 | MEDIUM | 6.2 | 0.2% | Dec 3, 2025 | Aquarius Desktop 3.0.069 for macOS stores user authentication credentials in the local file ~/Library/Application Suppor... |
| CVE-2025-62686 | MEDIUM | 6.2 | 0.2% | Dec 3, 2025 | A local privilege escalation vulnerability exists in the Plugin Alliance InstallationHelper service included with Plugin... |
| CVE-2025-55076 | MEDIUM | 6.2 | 0.2% | Dec 3, 2025 | A local privilege escalation vulnerability exists in the InstallationHelper service included with Plugin Alliance Instal... |
| CVE-2025-53965 | MEDIUM | 5.3 | 0.2% | Dec 3, 2025 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 220... |
| CVE-2025-20389 | MEDIUM | 6.5 | 0.4% | Dec 3, 2025 | In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and versions below 3.9.10, 3.8.58 and 3.7.28 of th... |
| CVE-2025-20387 | MEDIUM | 6.5 | 0.5% | Dec 3, 2025 | In Splunk Universal Forwarder for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an u... |
| CVE-2025-20386 | MEDIUM | 6.5 | 0.5% | Dec 3, 2025 | In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to... |
| CVE-2025-20385 | MEDIUM | 4.8 | 0.2% | Dec 3, 2025 | In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507... |
| CVE-2025-20384 | MEDIUM | 5.3 | 0.3% | Dec 3, 2025 | In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507... |
| CVE-2025-20383 | MEDIUM | 4.3 | 0.3% | Dec 3, 2025 | In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Sec... |
| CVE-2025-20382 | MEDIUM | 5.4 | 0.2% | Dec 3, 2025 | In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507... |
| CVE-2025-20381 | MEDIUM | 5.4 | 0.2% | Dec 3, 2025 | In Splunk MCP Server app versions below 0.2.4, a user with access to the "run_splunk_query" Model Context Protocol (MCP)... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now