2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66947 | MEDIUM | 6.5 | 0.3% | Dec 26, 2025 | SQL injection vulnerability in krishanmuraiji SMS v.1.0, within the /studentms/admin/edit-class-detail.php via the editi... |
| CVE-2025-65885 | MEDIUM | 5.1 | 0.1% | Dec 26, 2025 | An issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian Belle devices on Nokia 808 (Delight v1.8)... |
| CVE-2025-64645 | HIGH | 7.4 | 0.1% | Dec 26, 2025 | IBM Concert 1.0.0 through 2.1.0 could allow a local user to escalate their privileges due to a race condition of a symbo... |
| CVE-2025-36230 | MEDIUM | 5.4 | 0.2% | Dec 26, 2025 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTM... |
| CVE-2025-36229 | MEDIUM | 4.3 | 0.2% | Dec 26, 2025 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data du... |
| CVE-2025-36228 | LOW | 3.8 | 0.2% | Dec 26, 2025 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API... |
| CVE-2025-25341 | HIGH | 7.5 | 0.4% | Dec 26, 2025 | A vulnerability exists in the libxmljs 1.0.11 when parsing a specially crafted XML document. Accessing the internal _ref... |
| CVE-2025-36192 | HIGH | 7.1 | 0.1% | Dec 26, 2025 | IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM DS8900F ( R9.4) 89.40.83.089.42.18.089.... |
| CVE-2025-14687 | MEDIUM | 6.5 | 0.2% | Dec 26, 2025 | IBM Db2 Intelligence Center 1.1.0, 1.1.1, 1.1.2 could allow an authenticated user to perform unauthorized actions due to... |
| CVE-2025-13915 | CRITICAL | 9.8 | 8.7% | Dec 26, 2025 | IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanis... |
| CVE-2025-1721 | HIGH | 7.5 | 0.3% | Dec 26, 2025 | IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due ... |
| CVE-2025-12771 | HIGH | 7.8 | 0.1% | Dec 26, 2025 | IBM Concert 1.0.0 through 2.1.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A lo... |
| CVE-2025-67450 | HIGH | 7.8 | 0.1% | Dec 26, 2025 | Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software ... |
| CVE-2025-59888 | MEDIUM | 6.7 | 0.2% | Dec 26, 2025 | Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution ... |
| CVE-2025-59887 | HIGH | 8.6 | 0.3% | Dec 26, 2025 | Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code exec... |
| CVE-2025-62578 | HIGH | 7.5 | 0.4% | Dec 26, 2025 | DVP-12SE - Modbus/TCP Cleartext Transmission of Sensitive Information |
| CVE-2025-8075 | MEDIUM | 5.4 | 0.2% | Dec 26, 2025 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io... |
| CVE-2025-68946 | MEDIUM | 5.4 | 0.2% | Dec 26, 2025 | In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS. |
| CVE-2025-52601 | HIGH | 7.8 | 0.1% | Dec 26, 2025 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io... |
| CVE-2025-52600 | HIGH | 7.2 | 0.4% | Dec 26, 2025 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io... |
| CVE-2025-52599 | MEDIUM | 6.5 | 0.2% | Dec 26, 2025 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io... |
| CVE-2025-52598 | LOW | 3.7 | 0.2% | Dec 26, 2025 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io... |
| CVE-2025-68945 | MEDIUM | 5.3 | 0.3% | Dec 26, 2025 | In Gitea before 1.21.2, an anonymous user can visit a private user's project. |
| CVE-2025-68944 | MEDIUM | 5.3 | 0.3% | Dec 26, 2025 | Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package... |
| CVE-2025-68943 | MEDIUM | 5.3 | 0.3% | Dec 26, 2025 | Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now