2025 CVE Vulnerabilities
45,143 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63526 | MEDIUM | 5.4 | 0.3% | Dec 1, 2025 | A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System within the abs.php component. The ... |
| CVE-2025-63523 | MEDIUM | 6.5 | 0.2% | Dec 1, 2025 | FeehiCMS version 2.1.1 fails to enforce server-side immutability for parameters that are presented to clients as "read-o... |
| CVE-2025-63522 | MEDIUM | 4.6 | 0.2% | Dec 1, 2025 | Reverse Tabnabbing vulnerability in FeehiCMS 2.1.1 in the Comments Management function |
| CVE-2025-63520 | MEDIUM | 6.1 | 0.2% | Dec 1, 2025 | Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 via the id parameter of the User Update function (?r=user%2Fu... |
| CVE-2025-13129 | MEDIUM | 4.3 | 0.2% | Dec 1, 2025 | Improper Enforcement of Behavioral Workflow vulnerability in Seneka Software Hardware Information Technology Trade Contr... |
| CVE-2025-49643 | MEDIUM | 6.5 | 0.3% | Dec 1, 2025 | An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending sp... |
| CVE-2025-49642 | MEDIUM | 5.9 | 0.1% | Dec 1, 2025 | Library loading on AIX Zabbix Agent builds can be hijacked by local users with write access to the /home/cecuser directo... |
| CVE-2025-27232 | MEDIUM | 4.9 | 0.3% | Dec 1, 2025 | An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver le... |
| CVE-2025-58408 | MEDIUM | 5.9 | 0.1% | Dec 1, 2025 | Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger reads of stale data... |
| CVE-2025-13296 | MEDIUM | 5.4 | 0.1% | Dec 1, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Tekrom Technology Inc. T-Soft E-Commerce allows Cross Site Request Fo... |
| CVE-2025-8045 | MEDIUM | 4 | 0.2% | Dec 1, 2025 | Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver al... |
| CVE-2025-6349 | MEDIUM | 5.1 | 0.2% | Dec 1, 2025 | Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver al... |
| CVE-2025-41070 | MEDIUM | 4.8 | 0.2% | Dec 1, 2025 | Reflected Cross-site Scripting (XSS) vulnerability in Sanoma's Clickedu. This vulnerability allows an attacker to execut... |
| CVE-2025-2879 | MEDIUM | 5.1 | 0.1% | Dec 1, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd A... |
| CVE-2025-41739 | MEDIUM | 5.9 | 0.3% | Dec 1, 2025 | An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the C... |
| CVE-2025-13819 | MEDIUM | 6.1 | 0.2% | Dec 1, 2025 | Open redirect in the web server component of MiR Robot and Fleet software allows a remote attacker to redirect users to ... |
| CVE-2025-13809 | MEDIUM | 6.5 | 0.3% | Dec 1, 2025 | A vulnerability has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this is... |
| CVE-2025-13807 | MEDIUM | 4.3 | 0.3% | Dec 1, 2025 | A vulnerability was detected in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected is the funct... |
| CVE-2025-13804 | MEDIUM | 4.3 | 0.2% | Dec 1, 2025 | A security flaw has been discovered in nutzam NutzBoot up to 2.6.0-SNAPSHOT. The impacted element is an unknown function... |
| CVE-2025-13802 | MEDIUM | 4.3 | 0.3% | Dec 1, 2025 | A vulnerability was determined in jairiidriss RestaurantWebsite up to e7911f12d035e8e2f9a75e7a28b59e4ef5c1d654. Impacted... |
| CVE-2025-13796 | MEDIUM | 6.3 | 0.3% | Dec 1, 2025 | A security vulnerability has been detected in deco-cx apps up to 0.120.1. Affected by this vulnerability is the function... |
| CVE-2025-13793 | MEDIUM | 4.3 | 0.3% | Nov 30, 2025 | A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affec... |
| CVE-2025-13791 | MEDIUM | 6.5 | 0.4% | Nov 30, 2025 | A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org... |
| CVE-2025-13789 | MEDIUM | 5.3 | 0.3% | Nov 30, 2025 | A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model... |
| CVE-2025-13785 | MEDIUM | 6.5 | 0.3% | Nov 30, 2025 | A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5. This issue affects so... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now