2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68688 | — | — | — | Dec 24, 2025 | Rejected reason: Not used |
| CVE-2025-68687 | — | — | — | Dec 24, 2025 | Rejected reason: Not used |
| CVE-2025-15053 | HIGH | 7.3 | 0.3% | Dec 24, 2025 | A flaw has been found in code-projects Student Information System 1.0. This issue affects some unknown processing of the... |
| CVE-2025-15052 | MEDIUM | 5.4 | 0.2% | Dec 24, 2025 | A vulnerability was detected in code-projects Student Information System 1.0. This vulnerability affects unknown code of... |
| CVE-2025-15050 | HIGH | 8.8 | 0.3% | Dec 24, 2025 | A security vulnerability has been detected in code-projects Student File Management System 1.0. This affects an unknown ... |
| CVE-2025-68696 | HIGH | 8.2 | 0.3% | Dec 23, 2025 | httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of lea... |
| CVE-2025-68669 | CRITICAL | 9.6 | 0.4% | Dec 23, 2025 | 5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. In versions 0.15.2... |
| CVE-2025-68667 | CRITICAL | 9.9 | 0.5% | Dec 23, 2025 | Conduit is a chat server powered by Matrix. A vulnerability that affects a number of Conduit-derived homeservers allows ... |
| CVE-2025-68665 | CRITICAL | 9.1 | 0.7% | Dec 23, 2025 | LangChain is a framework for building LLM-powered applications. Prior to @langchain/core versions 0.3.80 and 1.1.8, and ... |
| CVE-2025-68664 | HIGH | 8.2 | 13.8% | Dec 23, 2025 | LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a seriali... |
| CVE-2025-68617 | HIGH | 7 | 0.2% | Dec 23, 2025 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From versions 2.5.0 to before 2.5.2, a rac... |
| CVE-2025-15049 | CRITICAL | 9.8 | 0.3% | Dec 23, 2025 | A vulnerability was identified in code-projects Online Farm System 1.0. Affected is an unknown function of the file /add... |
| CVE-2025-15048 | CRITICAL | 9.8 | 11.3% | Dec 23, 2025 | A vulnerability was determined in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/CheckTools ... |
| CVE-2025-66213 | HIGH | 8.8 | 3.0% | Dec 23, 2025 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0... |
| CVE-2025-66212 | HIGH | 8.8 | 3.2% | Dec 23, 2025 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0... |
| CVE-2025-66211 | HIGH | 8.8 | 2.7% | Dec 23, 2025 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0... |
| CVE-2025-66210 | HIGH | 8.8 | 2.7% | Dec 23, 2025 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0... |
| CVE-2025-66209 | HIGH | 8.8 | 3.8% | Dec 23, 2025 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0... |
| CVE-2025-15047 | CRITICAL | 9.8 | 1.1% | Dec 23, 2025 | A vulnerability was found in Tenda WH450 1.0.0.18. This affects an unknown function of the file /goform/PPTPDClient of t... |
| CVE-2025-15046 | CRITICAL | 9.8 | 1.0% | Dec 23, 2025 | A vulnerability has been found in Tenda WH450 1.0.0.18. The impacted element is an unknown function of the file /goform/... |
| CVE-2025-14501 | HIGH | 7.5 | 0.6% | Dec 23, 2025 | Sante PACS Server HTTP Content-Length Header Handling NULL Pointer Dereference Denial-of-Service Vulnerability. This vul... |
| CVE-2025-14500 | CRITICAL | 9.8 | 1.4% | Dec 23, 2025 | IceWarp14 X-File-Operation Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attac... |
| CVE-2025-14499 | HIGH | 8.8 | 0.7% | Dec 23, 2025 | IceWarp gmaps Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to by... |
| CVE-2025-14498 | HIGH | 7.8 | 0.1% | Dec 23, 2025 | TradingView Desktop Electron Uncontrolled Search Path Local Privilege Escalation Vulnerability. This vulnerability allow... |
| CVE-2025-14497 | HIGH | 7.8 | 0.2% | Dec 23, 2025 | RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability all... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now