2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66400 | MEDIUM | 5.3 | 0.3% | Dec 1, 2025 | mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classna... |
| CVE-2025-66312 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ... |
| CVE-2025-66311 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ... |
| CVE-2025-66310 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ... |
| CVE-2025-66309 | MEDIUM | 6.1 | 0.2% | Dec 1, 2025 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ... |
| CVE-2025-66308 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ... |
| CVE-2025-66307 | MEDIUM | 5.3 | 0.3% | Dec 1, 2025 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ... |
| CVE-2025-66306 | MEDIUM | 6.5 | 0.3% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerabi... |
| CVE-2025-66305 | MEDIUM | 4.9 | 0.3% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Denial of Service (DoS) vulnerability was identified in the... |
| CVE-2025-66303 | MEDIUM | 4.9 | 0.4% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A Denial of Service (DoS) vulnerability has been identified i... |
| CVE-2025-66302 | MEDIUM | 6.8 | 0.5% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CM... |
| CVE-2025-65622 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user ... |
| CVE-2025-65621 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes... |
| CVE-2025-58044 | MEDIUM | 6.1 | 0.4% | Dec 1, 2025 | JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and ... |
| CVE-2025-63317 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | Todoist v8896 is vulnerable to Cross Site Scripting (XSS) in /api/v1/uploads. Uploaded SVG files have no sanitization ap... |
| CVE-2025-12756 | MEDIUM | 4.3 | 0.2% | Dec 1, 2025 | Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user pe... |
| CVE-2025-65407 | MEDIUM | 6.5 | 0.2% | Dec 1, 2025 | A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows atta... |
| CVE-2025-11772 | MEDIUM | 6.6 | 0.1% | Dec 1, 2025 | A carefully crafted DLL, copied to C:\ProgramData\Synaptics folder, allows a local user to execute arbitrary code w... |
| CVE-2025-13837 | MEDIUM | 5.5 | 0.2% | Dec 1, 2025 | When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file... |
| CVE-2025-13835 | MEDIUM | 6.5 | 0.1% | Dec 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arc... |
| CVE-2025-13653 | MEDIUM | 4.3 | 0.2% | Dec 1, 2025 | In Search Guard FLX versions from 3.1.0 up to 4.0.0 with enterprise modules being disabled, there exists an issue which ... |
| CVE-2025-65408 | MEDIUM | 6.5 | 0.2% | Dec 1, 2025 | A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming M... |
| CVE-2025-65406 | MEDIUM | 6.5 | 0.3% | Dec 1, 2025 | A heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02 allow... |
| CVE-2025-65405 | MEDIUM | 6.5 | 0.3% | Dec 1, 2025 | A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows ... |
| CVE-2025-65404 | MEDIUM | 6.5 | 0.3% | Dec 1, 2025 | A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Deni... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now