2025 CVE Vulnerabilities
45,160 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14927 | HIGH | 7.8 | 0.3% | Dec 23, 2025 | Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability al... |
| CVE-2025-14926 | HIGH | 7.8 | 0.3% | Dec 23, 2025 | Hugging Face Transformers SEW convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allo... |
| CVE-2025-14925 | HIGH | 7.8 | 0.3% | Dec 23, 2025 | Hugging Face Accelerate Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows... |
| CVE-2025-14924 | HIGH | 7.8 | 0.3% | Dec 23, 2025 | Hugging Face Transformers megatron_gpt2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vuln... |
| CVE-2025-14922 | HIGH | 7.8 | 0.3% | Dec 23, 2025 | Hugging Face Diffusers CogView4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerabilit... |
| CVE-2025-14921 | HIGH | 7.8 | 0.3% | Dec 23, 2025 | Hugging Face Transformers Transformer-XL Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. Th... |
| CVE-2025-14920 | HIGH | 7.8 | 0.3% | Dec 23, 2025 | Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vu... |
| CVE-2025-11419 | HIGH | 7.5 | 0.7% | Dec 23, 2025 | A flaw was found in Keycloak. This vulnerability allows an unauthenticated remote attacker to cause a denial of service ... |
| CVE-2025-65354 | CRITICAL | 9.8 | 0.5% | Dec 23, 2025 | Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injecti... |
| CVE-2025-25364 | HIGH | 8.4 | 0.8% | Dec 23, 2025 | A command injection vulnerability in the me.connectify.SMJobBlessHelper XPC service of Speedify VPN up to v15.0.0 allows... |
| CVE-2025-10863 | — | — | — | Dec 23, 2025 | Rejected reason: This CVE id was assigned but later discarded. |
| CVE-2025-51511 | CRITICAL | 9.8 | 0.3% | Dec 23, 2025 | Cadmium CMS v.0.4.9 has a background arbitrary file upload vulnerability in /admin/content/filemanager/uploads. |
| CVE-2025-13074 | — | — | — | Dec 23, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2025-65713 | MEDIUM | 4 | 0.4% | Dec 23, 2025 | Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully val... |
| CVE-2025-65410 | MEDIUM | 6.2 | 0.2% | Dec 23, 2025 | A stack overflow in the src/main.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) v... |
| CVE-2025-33224 | CRITICAL | 9.8 | 0.7% | Dec 23, 2025 | NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges.... |
| CVE-2025-33223 | CRITICAL | 9.8 | 0.6% | Dec 23, 2025 | NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges.... |
| CVE-2025-33222 | CRITICAL | 9.8 | 0.5% | Dec 23, 2025 | NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit a hard-coded credential issue. A succes... |
| CVE-2025-29229 | CRITICAL | 9.8 | 1.1% | Dec 23, 2025 | linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus. |
| CVE-2025-29228 | CRITICAL | 9.8 | 1.1% | Dec 23, 2025 | Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter. |
| CVE-2025-67111 | HIGH | 7.5 | 0.3% | Dec 23, 2025 | An integer overflow in the RTPS protocol implementation of OpenDDS DDS before v3.33.0 allows attackers to cause a Denial... |
| CVE-2025-67109 | CRITICAL | 10 | 0.3% | Dec 23, 2025 | Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certifica... |
| CVE-2025-67108 | CRITICAL | 10 | 0.3% | Dec 23, 2025 | eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure commun... |
| CVE-2025-65865 | HIGH | 7.5 | 0.4% | Dec 23, 2025 | An integer overflow in eProsima Fast-DDS v3.3 allows attackers to cause a Denial of Service (DoS) via a crafted input. |
| CVE-2025-50526 | CRITICAL | 9.8 | 1.0% | Dec 23, 2025 | Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now