2025 CVE Vulnerabilities
45,155 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14180 | HIGH | 7.5 | 0.6% | Dec 27, 2025 | In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 w... |
| CVE-2025-14178 | HIGH | 8.2 | 0.4% | Dec 27, 2025 | In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, ... |
| CVE-2025-14177 | HIGH | 7.5 | 0.5% | Dec 27, 2025 | In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, ... |
| CVE-2025-15109 | HIGH | 7.3 | 0.3% | Dec 27, 2025 | A flaw has been found in jackq XCMS up to 3fab5342cc509945a7ce1b8ec39d19f701b89261. This impacts an unknown function of ... |
| CVE-2025-15108 | LOW | 3.7 | 0.3% | Dec 27, 2025 | A vulnerability was detected in PandaXGO PandaX up to fb8ff40f7ce5dfebdf66306c6d85625061faf7e5. This affects an unknown ... |
| CVE-2025-54322 | CRITICAL | 9.8 | 14.0% | Dec 27, 2025 | Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid paramete... |
| CVE-2025-15107 | HIGH | 8.1 | 0.6% | Dec 27, 2025 | A security vulnerability has been detected in actiontech sqle up to 4.2511.0. The impacted element is an unknown functio... |
| CVE-2025-15106 | MEDIUM | 4.3 | 0.3% | Dec 27, 2025 | A weakness has been identified in getmaxun maxun up to 0.0.28. The affected element is the function router.get of the fi... |
| CVE-2025-15105 | MEDIUM | 5.9 | 0.5% | Dec 27, 2025 | A security flaw has been discovered in getmaxun maxun up to 0.0.28. Impacted is an unknown function of the file /getmaxu... |
| CVE-2025-68952 | CRITICAL | 9.8 | 0.5% | Dec 27, 2025 | Eigent is a multi-agent Workforce. In version 0.0.60, a 1-click Remote Code Execution (RCE) vulnerability has been ident... |
| CVE-2025-68948 | HIGH | 8.1 | 0.2% | Dec 27, 2025 | SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note ... |
| CVE-2025-68927 | MEDIUM | 6.1 | 0.2% | Dec 27, 2025 | Libredesk is a self-hosted customer support desk. Prior to version 0.8.6-beta, LibreDesk is vulnerable to stored HTML in... |
| CVE-2025-59946 | HIGH | 7.5 | 0.3% | Dec 27, 2025 | NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing iss... |
| CVE-2025-68932 | CRITICAL | 9.8 | 0.5% | Dec 27, 2025 | FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random n... |
| CVE-2025-68474 | HIGH | 7.6 | 0.3% | Dec 27, 2025 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, ... |
| CVE-2025-68473 | HIGH | 8.6 | 0.4% | Dec 27, 2025 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, ... |
| CVE-2025-68148 | HIGH | 7.5 | 0.4% | Dec 27, 2025 | FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny ... |
| CVE-2025-66203 | CRITICAL | 9.1 | 0.7% | Dec 27, 2025 | StreamVault is a video download integration solution. Prior to version 251126, a Remote Code Execution (RCE) vulnerabili... |
| CVE-2025-68697 | MEDIUM | 5.4 | 0.2% | Dec 26, 2025 | n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code ... |
| CVE-2025-68668 | CRITICAL | 9.9 | 12.7% | Dec 26, 2025 | n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability e... |
| CVE-2025-67729 | HIGH | 8.8 | 0.5% | Dec 26, 2025 | LMDeploy is a toolkit for compressing, deploying, and serving LLMs. Prior to version 0.11.1, an insecure deserialization... |
| CVE-2025-61914 | MEDIUM | 5.4 | 0.2% | Dec 26, 2025 | n8n is an open source workflow automation platform. Prior to version 1.114.0, a stored Cross-Site Scripting (XSS) vulner... |
| CVE-2025-66737 | MEDIUM | 4.3 | 0.6% | Dec 26, 2025 | Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal. A remote normal privileged attacker can read arbi... |
| CVE-2025-67015 | HIGH | 7.5 | 0.4% | Dec 26, 2025 | Incorrect access control in Comtech EF Data CDM-625 / CDM-625A Advanced Satellite Modem with firmware v2.5.1 allows atta... |
| CVE-2025-67014 | HIGH | 7.5 | 0.5% | Dec 26, 2025 | Incorrect access control in DEV Systemtechnik GmbH DEV 7113 RF over Fiber Distribution System 32-0078 H.01 allows unauth... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now