2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54322 | CRITICAL | 9.8 | 14.0% | Dec 27, 2025 | Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid paramete... |
| CVE-2025-15107 | HIGH | 8.1 | 0.6% | Dec 27, 2025 | A security vulnerability has been detected in actiontech sqle up to 4.2511.0. The impacted element is an unknown functio... |
| CVE-2025-15106 | MEDIUM | 4.3 | 0.3% | Dec 27, 2025 | A weakness has been identified in getmaxun maxun up to 0.0.28. The affected element is the function router.get of the fi... |
| CVE-2025-15105 | MEDIUM | 5.9 | 0.5% | Dec 27, 2025 | A security flaw has been discovered in getmaxun maxun up to 0.0.28. Impacted is an unknown function of the file /getmaxu... |
| CVE-2025-68952 | CRITICAL | 9.8 | 0.5% | Dec 27, 2025 | Eigent is a multi-agent Workforce. In version 0.0.60, a 1-click Remote Code Execution (RCE) vulnerability has been ident... |
| CVE-2025-68948 | HIGH | 8.1 | 0.2% | Dec 27, 2025 | SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note ... |
| CVE-2025-68927 | MEDIUM | 6.1 | 0.2% | Dec 27, 2025 | Libredesk is a self-hosted customer support desk. Prior to version 0.8.6-beta, LibreDesk is vulnerable to stored HTML in... |
| CVE-2025-59946 | HIGH | 7.5 | 0.3% | Dec 27, 2025 | NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing iss... |
| CVE-2025-68932 | CRITICAL | 9.8 | 0.5% | Dec 27, 2025 | FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random n... |
| CVE-2025-68474 | HIGH | 7.6 | 0.3% | Dec 27, 2025 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, ... |
| CVE-2025-68473 | HIGH | 8.6 | 0.4% | Dec 27, 2025 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, ... |
| CVE-2025-68148 | HIGH | 7.5 | 0.4% | Dec 27, 2025 | FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny ... |
| CVE-2025-66203 | CRITICAL | 9.1 | 0.7% | Dec 27, 2025 | StreamVault is a video download integration solution. Prior to version 251126, a Remote Code Execution (RCE) vulnerabili... |
| CVE-2025-68697 | MEDIUM | 5.4 | 0.2% | Dec 26, 2025 | n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code ... |
| CVE-2025-68668 | CRITICAL | 9.9 | 12.7% | Dec 26, 2025 | n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability e... |
| CVE-2025-67729 | HIGH | 8.8 | 0.5% | Dec 26, 2025 | LMDeploy is a toolkit for compressing, deploying, and serving LLMs. Prior to version 0.11.1, an insecure deserialization... |
| CVE-2025-61914 | MEDIUM | 5.4 | 0.2% | Dec 26, 2025 | n8n is an open source workflow automation platform. Prior to version 1.114.0, a stored Cross-Site Scripting (XSS) vulner... |
| CVE-2025-66737 | MEDIUM | 4.3 | 0.6% | Dec 26, 2025 | Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal. A remote normal privileged attacker can read arbi... |
| CVE-2025-67015 | HIGH | 7.5 | 0.4% | Dec 26, 2025 | Incorrect access control in Comtech EF Data CDM-625 / CDM-625A Advanced Satellite Modem with firmware v2.5.1 allows atta... |
| CVE-2025-67014 | HIGH | 7.5 | 0.5% | Dec 26, 2025 | Incorrect access control in DEV Systemtechnik GmbH DEV 7113 RF over Fiber Distribution System 32-0078 H.01 allows unauth... |
| CVE-2025-67013 | MEDIUM | 6.5 | 0.2% | Dec 26, 2025 | The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not impleme... |
| CVE-2025-66738 | HIGH | 8.8 | 0.6% | Dec 26, 2025 | An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a ... |
| CVE-2025-57403 | HIGH | 7.5 | 1.0% | Dec 26, 2025 | Cola Dnslog v1.3.2 is vulnerable to Directory Traversal. When a DNS query for a TXT record is processed, the application... |
| CVE-2025-13158 | CRITICAL | 9.3 | 0.4% | Dec 26, 2025 | Prototype pollution vulnerability in apidoc-core versions 0.2.0 and all subsequent versions allows remote attackers to m... |
| CVE-2025-67349 | MEDIUM | 6.1 | 0.3% | Dec 26, 2025 | A cross-site scripting (XSS) vulnerability was identified in FluentCMS 1.2.3. After logging in as an admin and navigatin... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now