2025 CVE Vulnerabilities
45,155 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67013 | MEDIUM | 6.5 | 0.2% | Dec 26, 2025 | The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not impleme... |
| CVE-2025-66738 | HIGH | 8.8 | 0.6% | Dec 26, 2025 | An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a ... |
| CVE-2025-57403 | HIGH | 7.5 | 1.0% | Dec 26, 2025 | Cola Dnslog v1.3.2 is vulnerable to Directory Traversal. When a DNS query for a TXT record is processed, the application... |
| CVE-2025-13158 | CRITICAL | 9.3 | 0.4% | Dec 26, 2025 | Prototype pollution vulnerability in apidoc-core versions 0.2.0 and all subsequent versions allows remote attackers to m... |
| CVE-2025-67349 | MEDIUM | 6.1 | 0.3% | Dec 26, 2025 | A cross-site scripting (XSS) vulnerability was identified in FluentCMS 1.2.3. After logging in as an admin and navigatin... |
| CVE-2025-66947 | MEDIUM | 6.5 | 0.3% | Dec 26, 2025 | SQL injection vulnerability in krishanmuraiji SMS v.1.0, within the /studentms/admin/edit-class-detail.php via the editi... |
| CVE-2025-65885 | MEDIUM | 5.1 | 0.1% | Dec 26, 2025 | An issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian Belle devices on Nokia 808 (Delight v1.8)... |
| CVE-2025-64645 | HIGH | 7.4 | 0.1% | Dec 26, 2025 | IBM Concert 1.0.0 through 2.1.0 could allow a local user to escalate their privileges due to a race condition of a symbo... |
| CVE-2025-36230 | MEDIUM | 5.4 | 0.2% | Dec 26, 2025 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTM... |
| CVE-2025-36229 | MEDIUM | 4.3 | 0.2% | Dec 26, 2025 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data du... |
| CVE-2025-36228 | LOW | 3.8 | 0.2% | Dec 26, 2025 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API... |
| CVE-2025-25341 | HIGH | 7.5 | 0.4% | Dec 26, 2025 | A vulnerability exists in the libxmljs 1.0.11 when parsing a specially crafted XML document. Accessing the internal _ref... |
| CVE-2025-36192 | HIGH | 7.1 | 0.1% | Dec 26, 2025 | IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM DS8900F ( R9.4) 89.40.83.089.42.18.089.... |
| CVE-2025-14687 | MEDIUM | 6.5 | 0.2% | Dec 26, 2025 | IBM Db2 Intelligence Center 1.1.0, 1.1.1, 1.1.2 could allow an authenticated user to perform unauthorized actions due to... |
| CVE-2025-13915 | CRITICAL | 9.8 | 8.7% | Dec 26, 2025 | IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanis... |
| CVE-2025-1721 | HIGH | 7.5 | 0.3% | Dec 26, 2025 | IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due ... |
| CVE-2025-12771 | HIGH | 7.8 | 0.1% | Dec 26, 2025 | IBM Concert 1.0.0 through 2.1.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A lo... |
| CVE-2025-67450 | HIGH | 7.8 | 0.1% | Dec 26, 2025 | Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software ... |
| CVE-2025-59888 | MEDIUM | 6.7 | 0.2% | Dec 26, 2025 | Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution ... |
| CVE-2025-59887 | HIGH | 8.6 | 0.3% | Dec 26, 2025 | Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code exec... |
| CVE-2025-62578 | HIGH | 7.5 | 0.4% | Dec 26, 2025 | DVP-12SE - Modbus/TCP Cleartext Transmission of Sensitive Information |
| CVE-2025-8075 | MEDIUM | 5.4 | 0.2% | Dec 26, 2025 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io... |
| CVE-2025-68946 | MEDIUM | 5.4 | 0.2% | Dec 26, 2025 | In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS. |
| CVE-2025-52601 | HIGH | 7.8 | 0.1% | Dec 26, 2025 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io... |
| CVE-2025-52600 | HIGH | 7.2 | 0.4% | Dec 26, 2025 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now