2025 CVE Vulnerabilities
45,143 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66305 | MEDIUM | 4.9 | 0.3% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Denial of Service (DoS) vulnerability was identified in the... |
| CVE-2025-66303 | MEDIUM | 4.9 | 0.3% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A Denial of Service (DoS) vulnerability has been identified i... |
| CVE-2025-66302 | MEDIUM | 6.8 | 0.4% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CM... |
| CVE-2025-65622 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user ... |
| CVE-2025-65621 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes... |
| CVE-2025-58044 | MEDIUM | 6.1 | 0.4% | Dec 1, 2025 | JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and ... |
| CVE-2025-63317 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | Todoist v8896 is vulnerable to Cross Site Scripting (XSS) in /api/v1/uploads. Uploaded SVG files have no sanitization ap... |
| CVE-2025-12756 | MEDIUM | 4.3 | 0.2% | Dec 1, 2025 | Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user pe... |
| CVE-2025-65407 | MEDIUM | 6.5 | 0.2% | Dec 1, 2025 | A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows atta... |
| CVE-2025-11772 | MEDIUM | 6.6 | 0.1% | Dec 1, 2025 | A carefully crafted DLL, copied to C:\ProgramData\Synaptics folder, allows a local user to execute arbitrary code w... |
| CVE-2025-13837 | MEDIUM | 5.5 | 0.2% | Dec 1, 2025 | When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file... |
| CVE-2025-13835 | MEDIUM | 6.5 | 0.1% | Dec 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arc... |
| CVE-2025-13653 | MEDIUM | 4.3 | 0.2% | Dec 1, 2025 | In Search Guard FLX versions from 3.1.0 up to 4.0.0 with enterprise modules being disabled, there exists an issue which ... |
| CVE-2025-65408 | MEDIUM | 6.5 | 0.2% | Dec 1, 2025 | A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming M... |
| CVE-2025-65406 | MEDIUM | 6.5 | 0.3% | Dec 1, 2025 | A heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02 allow... |
| CVE-2025-65405 | MEDIUM | 6.5 | 0.3% | Dec 1, 2025 | A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows ... |
| CVE-2025-65404 | MEDIUM | 6.5 | 0.3% | Dec 1, 2025 | A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Deni... |
| CVE-2025-65403 | MEDIUM | 6.5 | 0.3% | Dec 1, 2025 | A buffer overflow in the g_cfg.MaxUsers component of LightFTP v2.0 allows attackers to cause a Denial of Service (DoS) v... |
| CVE-2025-63534 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the login.php component... |
| CVE-2025-63533 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php a... |
| CVE-2025-63095 | MEDIUM | 6.5 | 0.3% | Dec 1, 2025 | Improper input validation in the BitstreamWriter::write_bits() function of Tempus Ex hello-video-codec v0.1.0 allows att... |
| CVE-2025-20085 | MEDIUM | 6.5 | 0.2% | Dec 1, 2025 | A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. ... |
| CVE-2025-64030 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | Eximbills Enterprise 4.1.5 (Built on 2020-10-30) is vulnerable to authenticated stored cross-site scripting (CWE-79) via... |
| CVE-2025-63528 | MEDIUM | 5.4 | 0.3% | Dec 1, 2025 | A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the blooddinfo.php comp... |
| CVE-2025-63527 | MEDIUM | 5.4 | 0.3% | Dec 1, 2025 | A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now