2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66237 | MEDIUM | 6.7 | 0.1% | Dec 4, 2025 | DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to... |
| CVE-2025-65959 | MEDIUM | 5.4 | 0.2% | Dec 4, 2025 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a St... |
| CVE-2025-65806 | MEDIUM | 4.3 | 0.3% | Dec 4, 2025 | The E-POINT CMS eagle.gsam-1169.1 file upload feature improperly handles nested archive files. An attacker can upload a ... |
| CVE-2025-63499 | MEDIUM | 6.1 | 0.3% | Dec 4, 2025 | Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter. |
| CVE-2025-12996 | MEDIUM | 4.1 | 0.1% | Dec 4, 2025 | Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext ... |
| CVE-2025-12994 | MEDIUM | 5.3 | 0.3% | Dec 4, 2025 | Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an ... |
| CVE-2025-63361 | MEDIUM | 5.7 | 0.3% | Dec 4, 2025 | Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.00... |
| CVE-2025-59788 | MEDIUM | 5.4 | 0.2% | Dec 4, 2025 | Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions bef... |
| CVE-2025-14013 | MEDIUM | 4.8 | 0.2% | Dec 4, 2025 | A vulnerability was identified in JIZHICMS up to 2.5.5. The impacted element is an unknown function of the file /index.p... |
| CVE-2025-13488 | MEDIUM | 5.1 | 0.3% | Dec 4, 2025 | Due to a regression introduced in version 3.83.0, a security header is no longer applied to certain user-uploaded conten... |
| CVE-2025-9127 | MEDIUM | 5.5 | 0.1% | Dec 4, 2025 | A vulnerability exists in PX Enterprise whereby sensitive information may be logged under specific conditions. |
| CVE-2025-66373 | MEDIUM | 4.8 | 0.2% | Dec 4, 2025 | Akamai Ghost on Akamai CDN edge servers before 2025-11-17 has a chunked request body processing error that can result in... |
| CVE-2025-8074 | MEDIUM | 5.6 | 0.1% | Dec 4, 2025 | Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users... |
| CVE-2025-65516 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | A stored cross-site scripting (XSS) vulnerability was discovered in Seafile Community Edition prior to version 13.0.12. ... |
| CVE-2025-63681 | MEDIUM | 4.3 | 0.3% | Dec 4, 2025 | open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tas... |
| CVE-2025-61148 | MEDIUM | 6.5 | 0.3% | Dec 4, 2025 | An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authentic... |
| CVE-2025-40251 | MEDIUM | 5.5 | 0.1% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: devlink: rate: Unset parent pointer in devl_rate_no... |
| CVE-2025-2848 | MEDIUM | 6.3 | 0.4% | Dec 4, 2025 | A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, ... |
| CVE-2025-29845 | MEDIUM | 4.3 | 0.4% | Dec 4, 2025 | A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files. |
| CVE-2025-29844 | MEDIUM | 4.3 | 0.4% | Dec 4, 2025 | A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information. |
| CVE-2025-29843 | MEDIUM | 5.4 | 0.4% | Dec 4, 2025 | A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files. |
| CVE-2025-14007 | MEDIUM | 6.1 | 0.3% | Dec 4, 2025 | A vulnerability was detected in dayrui XunRuiCMS up to 4.7.1. This affects an unknown part of the file /admin79f2ec220c7... |
| CVE-2025-14006 | MEDIUM | 6.1 | 0.3% | Dec 4, 2025 | A security vulnerability has been detected in dayrui XunRuiCMS up to 4.7.1. Affected by this issue is some unknown funct... |
| CVE-2025-14005 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | A weakness has been identified in dayrui XunRuiCMS up to 4.7.1. Affected by this vulnerability is an unknown functionali... |
| CVE-2025-11222 | MEDIUM | 6.1 | 0.1% | Dec 4, 2025 | Central Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to u... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now