2025 CVE Vulnerabilities
45,143 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65657 | MEDIUM | 6.5 | 0.3% | Dec 2, 2025 | FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1... |
| CVE-2025-65380 | MEDIUM | 6.5 | 0.2% | Dec 2, 2025 | PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username... |
| CVE-2025-65379 | MEDIUM | 6.5 | 0.2% | Dec 2, 2025 | PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the /admin/password-recovery.php endpoint. Specifically,... |
| CVE-2025-66468 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior ... |
| CVE-2025-66460 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call eac... |
| CVE-2025-66459 | MEDIUM | 6.1 | 0.3% | Dec 2, 2025 | Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call eac... |
| CVE-2025-66458 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call eac... |
| CVE-2025-66454 | MEDIUM | 6.5 | 0.3% | Dec 2, 2025 | Arcade MCP allows you to to create, deploy, and share MCP Servers. Prior to 1.5.4, the arcade-mcp HTTP server uses a har... |
| CVE-2025-57850 | MEDIUM | 6.4 | 0.2% | Dec 2, 2025 | A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/p... |
| CVE-2025-13637 | MEDIUM | 4.3 | 0.2% | Dec 2, 2025 | Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convince... |
| CVE-2025-13636 | MEDIUM | 4.3 | 0.2% | Dec 2, 2025 | Inappropriate implementation in Split View in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinc... |
| CVE-2025-13635 | MEDIUM | 4.4 | 0.1% | Dec 2, 2025 | Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a local attacker to perform UI... |
| CVE-2025-13634 | MEDIUM | 4.4 | 0.1% | Dec 2, 2025 | Inappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41 allowed a local attacker to... |
| CVE-2025-13632 | MEDIUM | 5.4 | 0.2% | Dec 2, 2025 | Inappropriate implementation in DevTools in Google Chrome prior to 143.0.7499.41 allowed an attacker who convinced a use... |
| CVE-2025-65881 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | Sourcecodester Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /classes/Login.php. |
| CVE-2025-65215 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | Sourcecodester Web-based Pharmacy Product Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /product... |
| CVE-2025-65105 | MEDIUM | 5.3 | 0.2% | Dec 2, 2025 | Apptainer is an open source container platform. In Apptainer versions less than 1.4.5, a container can disable two of th... |
| CVE-2025-64750 | MEDIUM | 4.5 | 0.1% | Dec 2, 2025 | SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.3.5 and SingularityPRO 4.... |
| CVE-2025-52622 | MEDIUM | 5.4 | 0.1% | Dec 2, 2025 | The BigFix SaaS's HTTP responses were missing some security headers. The absence of these headers weakens the applicatio... |
| CVE-2025-65186 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page con... |
| CVE-2025-64070 | MEDIUM | 5.4 | 0.2% | Dec 2, 2025 | Sourcecodester Student Grades Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the Add New Subject ... |
| CVE-2025-65187 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authentica... |
| CVE-2025-63872 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | DeepSeek V3.2 has a Cross Site Scripting (XSS) vulnerability, which allows JavaScript execution through model-generated ... |
| CVE-2025-59704 | MEDIUM | 4.6 | 0.2% | Dec 2, 2025 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow an attacker to gain access the ... |
| CVE-2025-58113 | MEDIUM | 6.5 | 0.3% | Dec 2, 2025 | An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Co. Ltd PDF-XChange Editor 10.7.3.401... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now