2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10863 | — | — | — | Dec 23, 2025 | Rejected reason: This CVE id was assigned but later discarded. |
| CVE-2025-51511 | CRITICAL | 9.8 | 0.3% | Dec 23, 2025 | Cadmium CMS v.0.4.9 has a background arbitrary file upload vulnerability in /admin/content/filemanager/uploads. |
| CVE-2025-13074 | — | — | — | Dec 23, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2025-65713 | MEDIUM | 4 | 0.4% | Dec 23, 2025 | Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully val... |
| CVE-2025-65410 | MEDIUM | 6.2 | 0.2% | Dec 23, 2025 | A stack overflow in the src/main.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) v... |
| CVE-2025-33224 | CRITICAL | 9.8 | 0.7% | Dec 23, 2025 | NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges.... |
| CVE-2025-33223 | CRITICAL | 9.8 | 0.6% | Dec 23, 2025 | NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges.... |
| CVE-2025-33222 | CRITICAL | 9.8 | 0.5% | Dec 23, 2025 | NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit a hard-coded credential issue. A succes... |
| CVE-2025-29229 | CRITICAL | 9.8 | 1.1% | Dec 23, 2025 | linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus. |
| CVE-2025-29228 | CRITICAL | 9.8 | 1.1% | Dec 23, 2025 | Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter. |
| CVE-2025-67111 | HIGH | 7.5 | 0.3% | Dec 23, 2025 | An integer overflow in the RTPS protocol implementation of OpenDDS DDS before v3.33.0 allows attackers to cause a Denial... |
| CVE-2025-67109 | CRITICAL | 10 | 0.3% | Dec 23, 2025 | Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certifica... |
| CVE-2025-67108 | CRITICAL | 10 | 0.3% | Dec 23, 2025 | eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure commun... |
| CVE-2025-65865 | HIGH | 7.5 | 0.4% | Dec 23, 2025 | An integer overflow in eProsima Fast-DDS v3.3 allows attackers to cause a Denial of Service (DoS) via a crafted input. |
| CVE-2025-50526 | CRITICAL | 9.8 | 1.0% | Dec 23, 2025 | Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function. |
| CVE-2025-48864 | — | — | — | Dec 23, 2025 | Rejected reason: This CVE id was assigned but later discarded. |
| CVE-2025-48863 | — | — | — | Dec 23, 2025 | Rejected reason: This CVE id was assigned but later discarded. |
| CVE-2025-45493 | MEDIUM | 6.5 | 0.8% | Dec 23, 2025 | Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the iface parameter in the action_bandwidth function. |
| CVE-2025-68343 | — | — | 0.2% | Dec 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): check ... |
| CVE-2025-68342 | — | — | 0.2% | Dec 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): check ... |
| CVE-2025-68341 | CRITICAL | 9.8 | 0.2% | Dec 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: veth: reduce XDP no_direct return section to fix ra... |
| CVE-2025-68340 | MEDIUM | 5.5 | 0.1% | Dec 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: team: Move team device type change at the end of te... |
| CVE-2025-68339 | — | — | 0.2% | Dec 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: atm/fore200e: Fix possible data race in fore200e_op... |
| CVE-2025-68338 | — | — | 0.2% | Dec 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: dsa: microchip: Don't free uninitialized ksz_i... |
| CVE-2025-66845 | MEDIUM | 6.1 | 0.2% | Dec 23, 2025 | A reflected Cross-Site Scripting (XSS) vulnerability has been identified in TechStore version 1.0. The user_name endpoin... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now