2025 CVE Vulnerabilities
45,160 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67418 | CRITICAL | 9.8 | 0.6% | Dec 22, 2025 | ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded... |
| CVE-2025-67291 | MEDIUM | 6.1 | 0.2% | Dec 22, 2025 | A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute a... |
| CVE-2025-67290 | MEDIUM | 6.1 | 0.2% | Dec 22, 2025 | A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to e... |
| CVE-2025-65837 | MEDIUM | 5.4 | 0.1% | Dec 22, 2025 | PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in the Content Search module. |
| CVE-2025-65790 | MEDIUM | 6.1 | 0.2% | Dec 22, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in FuguHub 8.1 when serving SVG files through the /fs/ file ... |
| CVE-2025-67288 | CRITICAL | 10 | 0.5% | Dec 22, 2025 | An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a ... |
| CVE-2025-63664 | HIGH | 7.5 | 0.2% | Dec 22, 2025 | Incorrect access control in the /api/v1/conversations/*/messages API of GT Edge AI Platform before v2.0.10-dev allows un... |
| CVE-2025-63663 | HIGH | 7.5 | 0.2% | Dec 22, 2025 | Incorrect access control in the /api/v1/conversations/*/files API of GT Edge AI Platform before v2.0.10 allows unauthori... |
| CVE-2025-63662 | HIGH | 7.5 | 0.3% | Dec 22, 2025 | Insecure permissions in the /api/v1/agents API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers t... |
| CVE-2025-26787 | MEDIUM | 4.7 | 0.1% | Dec 22, 2025 | An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CL... |
| CVE-2025-15033 | MEDIUM | 6.5 | 0.3% | Dec 22, 2025 | A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on si... |
| CVE-2025-68645 | HIGH | 8.8 | 31.8% | Dec 22, 2025 | A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 ... |
| CVE-2025-67289 | CRITICAL | 9.6 | 0.4% | Dec 22, 2025 | An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execut... |
| CVE-2025-65270 | MEDIUM | 6.1 | 0.2% | Dec 22, 2025 | Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC 3.0 and 2.2.3, allowing an unauthenticated remote ... |
| CVE-2025-68337 | HIGH | 7.5 | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: jbd2: avoid bug_on in jbd2_journal_get_create_acces... |
| CVE-2025-68336 | HIGH | 7.5 | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: locking/spinlock/debug: Fix data-race in do_raw_wri... |
| CVE-2025-68335 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: comedi: pcl818: fix null-ptr-deref in pcl818_ai_can... |
| CVE-2025-68334 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Add support for Van Gogh SoC ... |
| CVE-2025-68333 | MEDIUM | 5.5 | 0.1% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix possible deadlock in the deferred_ir... |
| CVE-2025-68332 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: comedi: c6xdigio: Fix invalid PNP driver unregistra... |
| CVE-2025-68331 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: uas: fix urb unmapping issue when the uas devi... |
| CVE-2025-68330 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: iio: accel: bmc150: Fix irq assumption regression ... |
| CVE-2025-68329 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fix WARN_ON in tracing_buffers_mmap_close ... |
| CVE-2025-68328 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: firmware: stratix10-svc: fix bug in saving controll... |
| CVE-2025-68327 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: renesas_usbhs: Fix synchronous external abort ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now