2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15033 | MEDIUM | 6.5 | 0.3% | Dec 22, 2025 | A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on si... |
| CVE-2025-68645 | HIGH | 8.8 | 31.8% | Dec 22, 2025 | A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 ... |
| CVE-2025-67289 | CRITICAL | 9.6 | 0.4% | Dec 22, 2025 | An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execut... |
| CVE-2025-65270 | MEDIUM | 6.1 | 0.2% | Dec 22, 2025 | Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC 3.0 and 2.2.3, allowing an unauthenticated remote ... |
| CVE-2025-68337 | HIGH | 7.5 | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: jbd2: avoid bug_on in jbd2_journal_get_create_acces... |
| CVE-2025-68336 | HIGH | 7.5 | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: locking/spinlock/debug: Fix data-race in do_raw_wri... |
| CVE-2025-68335 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: comedi: pcl818: fix null-ptr-deref in pcl818_ai_can... |
| CVE-2025-68334 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Add support for Van Gogh SoC ... |
| CVE-2025-68333 | MEDIUM | 5.5 | 0.1% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix possible deadlock in the deferred_ir... |
| CVE-2025-68332 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: comedi: c6xdigio: Fix invalid PNP driver unregistra... |
| CVE-2025-68331 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: uas: fix urb unmapping issue when the uas devi... |
| CVE-2025-68330 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: iio: accel: bmc150: Fix irq assumption regression ... |
| CVE-2025-68329 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fix WARN_ON in tracing_buffers_mmap_close ... |
| CVE-2025-68328 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: firmware: stratix10-svc: fix bug in saving controll... |
| CVE-2025-68327 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: renesas_usbhs: Fix synchronous external abort ... |
| CVE-2025-68326 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Fix stack_depot usage Add missing stac... |
| CVE-2025-67443 | MEDIUM | 6.1 | 0.2% | Dec 22, 2025 | Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the lo... |
| CVE-2025-10021 | HIGH | 7 | 0.1% | Dec 22, 2025 | A Use of Uninitialized Variable vulnerability exists in Open Design Alliance Drawings SDK static versions (mt) before 20... |
| CVE-2025-67826 | HIGH | 7.7 | 0.1% | Dec 22, 2025 | An issue was discovered in K7 Ultimate Security 17.0.2045. A Local Privilege Escalation (LPE) vulnerability in the K7 Ul... |
| CVE-2025-61740 | HIGH | 7.2 | 0.1% | Dec 22, 2025 | Authentication issue that does not verify the source of a packet which could allow an attacker to create a denial-of-ser... |
| CVE-2025-26379 | HIGH | 7.2 | 0.2% | Dec 22, 2025 | Use of a weak pseudo-random number generator, which may allow an attacker to read or inject encrypted PowerG packets. |
| CVE-2025-14018 | HIGH | 7.3 | 0.4% | Dec 22, 2025 | Unquoted Search Path or Element vulnerability in NetBT Consulting Services Inc. E-Fatura allows Leveraging/Manipulating ... |
| CVE-2025-14273 | HIGH | 8.3 | 0.2% | Dec 22, 2025 | Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enab... |
| CVE-2025-8460 | MEDIUM | 4.8 | 0.2% | Dec 22, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-61739 | HIGH | 7.2 | 0.2% | Dec 22, 2025 | Due to Nonce reuse, attackers can perform reply attack or decrypt captured packets. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now