2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67743 | MEDIUM | 6.5 | 0.3% | Dec 23, 2025 | Local Deep Research is an AI-powered research assistant for deep, iterative research. In versions from 1.3.0 to before 1... |
| CVE-2025-15034 | CRITICAL | 9.8 | 0.3% | Dec 23, 2025 | A security flaw has been discovered in itsourcecode Student Management System 1.0. This affects an unknown part of the f... |
| CVE-2025-68615 | CRITICAL | 9.8 | 42.7% | Dec 23, 2025 | net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted pac... |
| CVE-2025-68614 | MEDIUM | 5.4 | 3.4% | Dec 23, 2025 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.12.0, the Alert Rule A... |
| CVE-2025-68480 | MEDIUM | 5.3 | 0.3% | Dec 22, 2025 | Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions fro... |
| CVE-2025-68476 | HIGH | 8.2 | 0.6% | Dec 22, 2025 | KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Re... |
| CVE-2025-68475 | HIGH | 7.5 | 0.6% | Dec 22, 2025 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.6.13, 1.7.... |
| CVE-2025-67436 | MEDIUM | 6.5 | 0.5% | Dec 22, 2025 | Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inj... |
| CVE-2025-65857 | HIGH | 7.5 | 0.4% | Dec 22, 2025 | An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetS... |
| CVE-2025-65856 | CRITICAL | 9.8 | 0.7% | Dec 22, 2025 | Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.... |
| CVE-2025-34458 | HIGH | 8.7 | 0.5% | Dec 22, 2025 | wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vul... |
| CVE-2025-34457 | HIGH | 8.7 | 0.5% | Dec 22, 2025 | wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 694c954, contain a stack-based buffer over... |
| CVE-2025-66736 | HIGH | 7.1 | 0.3% | Dec 22, 2025 | youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does n... |
| CVE-2025-66735 | HIGH | 7.5 | 0.4% | Dec 22, 2025 | youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does n... |
| CVE-2025-65817 | HIGH | 8.8 | 0.3% | Dec 22, 2025 | LSC Smart Connect Indoor IP Camera 1.4.13 contains a RCE vulnerability in start_app.sh. |
| CVE-2025-67418 | CRITICAL | 9.8 | 0.6% | Dec 22, 2025 | ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded... |
| CVE-2025-67291 | MEDIUM | 6.1 | 0.2% | Dec 22, 2025 | A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute a... |
| CVE-2025-67290 | MEDIUM | 6.1 | 0.2% | Dec 22, 2025 | A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to e... |
| CVE-2025-65837 | MEDIUM | 5.4 | 0.1% | Dec 22, 2025 | PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in the Content Search module. |
| CVE-2025-65790 | MEDIUM | 6.1 | 0.2% | Dec 22, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in FuguHub 8.1 when serving SVG files through the /fs/ file ... |
| CVE-2025-67288 | CRITICAL | 10 | 0.5% | Dec 22, 2025 | An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a ... |
| CVE-2025-63664 | HIGH | 7.5 | 0.2% | Dec 22, 2025 | Incorrect access control in the /api/v1/conversations/*/messages API of GT Edge AI Platform before v2.0.10-dev allows un... |
| CVE-2025-63663 | HIGH | 7.5 | 0.2% | Dec 22, 2025 | Incorrect access control in the /api/v1/conversations/*/files API of GT Edge AI Platform before v2.0.10 allows unauthori... |
| CVE-2025-63662 | HIGH | 7.5 | 0.3% | Dec 22, 2025 | Insecure permissions in the /api/v1/agents API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers t... |
| CVE-2025-26787 | MEDIUM | 4.7 | 0.1% | Dec 22, 2025 | An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CL... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now