2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15263 | CRITICAL | 9.8 | 0.3% | Dec 30, 2025 | A weakness has been identified in BiggiDroid Simple PHP CMS 1.0. Affected is an unknown function of the file /admin/logi... |
| CVE-2025-65411 | HIGH | 7.5 | 0.5% | Dec 30, 2025 | A NULL pointer dereference in the src/path.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Servi... |
| CVE-2025-65409 | HIGH | 7.5 | 0.3% | Dec 30, 2025 | A divide-by-zero in the encryption/decryption routines of GNU Recutils v1.9 allows attackers to cause a Denial of Servic... |
| CVE-2025-56332 | CRITICAL | 9.1 | 0.4% | Dec 30, 2025 | Authentication Bypass in fosrl/pangolin v1.6.2 and before allows attackers to access Pangolin resource via Insecure Defa... |
| CVE-2025-15262 | HIGH | 7.2 | 0.3% | Dec 30, 2025 | A security flaw has been discovered in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admi... |
| CVE-2025-15258 | MEDIUM | 6.1 | 0.2% | Dec 30, 2025 | A weakness has been identified in Edimax BR-6208AC 1.02/1.03. Affected by this issue is the function formALGSetup of the... |
| CVE-2025-69204 | HIGH | 7.5 | 0.5% | Dec 30, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12... |
| CVE-2025-68950 | MEDIUM | 6.2 | 0.2% | Dec 30, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12... |
| CVE-2025-68926 | CRITICAL | 9.8 | 29.0% | Dec 30, 2025 | RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC... |
| CVE-2025-68618 | HIGH | 7.5 | 0.6% | Dec 30, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12... |
| CVE-2025-66848 | CRITICAL | 9.8 | 1.0% | Dec 30, 2025 | JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier... |
| CVE-2025-66103 | MEDIUM | 6.5 | 0.2% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revmakx WPCal.io w... |
| CVE-2025-66094 | MEDIUM | 6.5 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dmccan Yada Wiki y... |
| CVE-2025-65925 | MEDIUM | 6.5 | 0.2% | Dec 30, 2025 | An issue was discovered in Zeroheight (SaaS) prior to 2025-06-13. A legacy user creation API pathway allowed accounts to... |
| CVE-2025-62128 | MEDIUM | 4.3 | 0.3% | Dec 30, 2025 | Missing Authorization vulnerability in SiteLock SiteLock Security – WP Hardening, Login Security & Malware Scans siteloc... |
| CVE-2025-62112 | MEDIUM | 4.3 | 0.1% | Dec 30, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Merv Barrett Import into Easy Property Listings easy-property-listing... |
| CVE-2025-59129 | HIGH | 7.6 | 0.3% | Dec 30, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appointify Appoint... |
| CVE-2025-52835 | CRITICAL | 9.6 | 0.2% | Dec 30, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ConoHa by GMO WING WordPress Migrator wing-migrator allows Upload a W... |
| CVE-2025-15257 | CRITICAL | 9.8 | 4.4% | Dec 30, 2025 | A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03. Affected by this vulnerability is the function formRo... |
| CVE-2025-15256 | CRITICAL | 9.8 | 3.3% | Dec 30, 2025 | A vulnerability was identified in Edimax BR-6208AC 1.02/1.03. Affected is the function formStaDrvSetup of the file /gofo... |
| CVE-2025-67746 | MEDIUM | 4.3 | 0.4% | Dec 30, 2025 | Composer is a dependency manager for PHP. In versions on the 2.x branch prior to 2.2.26 and 2.9.3, attackers controlling... |
| CVE-2025-66080 | MEDIUM | 5.3 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-con... |
| CVE-2025-64528 | MEDIUM | 5.3 | 0.2% | Dec 30, 2025 | Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who know... |
| CVE-2025-64190 | MEDIUM | 6.5 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core... |
| CVE-2025-63027 | MEDIUM | 6.5 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webcreations907 WB... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now