2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62753 | HIGH | 7.5 | 0.3% | Dec 30, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-59131 | HIGH | 7.1 | 0.1% | Dec 30, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in hoernerfranz WP-CalDav2ICS wp-caldav2ics allows Stored XSS.This issue... |
| CVE-2025-15114 | CRITICAL | 9.8 | 0.5% | Dec 30, 2025 | Ksenia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alar... |
| CVE-2025-15113 | CRITICAL | 9.3 | 0.4% | Dec 30, 2025 | Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that all... |
| CVE-2025-15112 | MEDIUM | 5.4 | 0.2% | Dec 30, 2025 | Ksenia Security lares (legacy model) version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that... |
| CVE-2025-15111 | CRITICAL | 9.8 | 0.5% | Dec 30, 2025 | Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized a... |
| CVE-2025-15360 | HIGH | 7.2 | 0.3% | Dec 30, 2025 | A vulnerability was determined in newbee-mall-plus 2.0.0. This impacts the function Upload of the file src/main/java/ltd... |
| CVE-2025-66723 | HIGH | 7.5 | 0.4% | Dec 30, 2025 | inMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Librar... |
| CVE-2025-61594 | HIGH | 7.5 | 0.5% | Dec 30, 2025 | URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Rub... |
| CVE-2025-15357 | CRITICAL | 9.8 | 3.8% | Dec 30, 2025 | A vulnerability was found in D-Link DI-7400G+ 19.12.25A1. This affects an unknown function of the file /msp_info.htm?fla... |
| CVE-2025-15356 | HIGH | 8.8 | 3.4% | Dec 30, 2025 | A vulnerability has been found in Tenda AC20 up to 16.03.08.12. The impacted element is the function sscanf of the file ... |
| CVE-2025-14987 | MEDIUM | 5.3 | 0.4% | Dec 30, 2025 | When system.enableCrossNamespaceCommands is enabled (on by default), the Temporal server permits certain workflow task c... |
| CVE-2025-14986 | LOW | 1.3 | 0.4% | Dec 30, 2025 | When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates... |
| CVE-2025-69261 | HIGH | 7.5 | 0.3% | Dec 30, 2025 | WasmEdge is a WebAssembly runtime. Prior to version 0.16.0-alpha.3, a multiplication in `WasmEdge/include/runtime/instan... |
| CVE-2025-69257 | MEDIUM | 6.7 | 0.1% | Dec 30, 2025 | theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to versi... |
| CVE-2025-69210 | MEDIUM | 5.4 | 1.0% | Dec 30, 2025 | FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.7, a stored cr... |
| CVE-2025-66823 | MEDIUM | 5.4 | 0.2% | Dec 30, 2025 | An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to... |
| CVE-2025-50343 | CRITICAL | 9.8 | 0.3% | Dec 30, 2025 | An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfie... |
| CVE-2025-15354 | CRITICAL | 9.8 | 0.3% | Dec 30, 2025 | A flaw has been found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the ... |
| CVE-2025-15353 | CRITICAL | 9.8 | 0.3% | Dec 30, 2025 | A vulnerability was detected in itsourcecode Society Management System 1.0. Impacted is the function edit_admin_query of... |
| CVE-2025-69256 | HIGH | 7.5 | 1.9% | Dec 30, 2025 | The Serverless Framework is a framework for using AWS Lambda and other managed cloud services to build applications. Sta... |
| CVE-2025-66835 | HIGH | 7.1 | 0.2% | Dec 30, 2025 | TrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary... |
| CVE-2025-66834 | HIGH | 7.3 | 0.3% | Dec 30, 2025 | A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadshe... |
| CVE-2025-66824 | HIGH | 8.7 | 0.3% | Dec 30, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference fun... |
| CVE-2025-15264 | HIGH | 7.3 | 0.3% | Dec 30, 2025 | A vulnerability was determined in FeehiCMS up to 2.1.1. Impacted is an unknown function of the file frontend/web/timthum... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now