2025 CVE Vulnerabilities
45,168 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66173 | MEDIUM | 6.2 | 0.2% | Dec 19, 2025 | There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of auth... |
| CVE-2025-14449 | MEDIUM | 6.4 | 0.2% | Dec 19, 2025 | The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's babe-search-fo... |
| CVE-2025-14267 | MEDIUM | 4.9 | 0.4% | Dec 19, 2025 | Incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server allows d... |
| CVE-2025-13999 | HIGH | 7.2 | 0.2% | Dec 19, 2025 | The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server-S... |
| CVE-2025-13754 | MEDIUM | 5.3 | 0.3% | Dec 19, 2025 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to Sensitive ... |
| CVE-2025-13008 | HIGH | 8.6 | 0.5% | Dec 19, 2025 | An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and ... |
| CVE-2025-13307 | HIGH | 7.2 | 0.5% | Dec 19, 2025 | The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic.... |
| CVE-2025-14546 | MEDIUM | 6.3 | 0.3% | Dec 19, 2025 | Versions of the package fastapi-sso before 0.19.0 are vulnerable to Cross-site Request Forgery (CSRF) due to the imprope... |
| CVE-2025-68491 | — | — | — | Dec 19, 2025 | Rejected reason: Not used |
| CVE-2025-68490 | — | — | — | Dec 19, 2025 | Rejected reason: Not used |
| CVE-2025-68489 | — | — | — | Dec 19, 2025 | Rejected reason: Not used |
| CVE-2025-68488 | — | — | — | Dec 19, 2025 | Rejected reason: Not used |
| CVE-2025-68487 | — | — | — | Dec 19, 2025 | Rejected reason: Not used |
| CVE-2025-68486 | — | — | — | Dec 19, 2025 | Rejected reason: Not used |
| CVE-2025-68485 | — | — | — | Dec 19, 2025 | Rejected reason: Not used |
| CVE-2025-68484 | — | — | — | Dec 19, 2025 | Rejected reason: Not used |
| CVE-2025-68483 | — | — | — | Dec 19, 2025 | Rejected reason: Not used |
| CVE-2025-14940 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | A vulnerability was determined in code-projects Scholars Tracking System 1.0. The affected element is an unknown functio... |
| CVE-2025-14939 | HIGH | 7.2 | 0.3% | Dec 19, 2025 | A vulnerability was found in code-projects Online Appointment Booking System 1.0. Impacted is an unknown function of the... |
| CVE-2025-67846 | MEDIUM | 6.5 | 0.4% | Dec 19, 2025 | The Deployment Infrastructure in Mintlify Platform before 2025-11-15 allows remote attackers to bypass security patches ... |
| CVE-2025-67845 | MEDIUM | 5.4 | 0.5% | Dec 19, 2025 | A Directory Traversal vulnerability in the Static Asset Proxy Endpoint in Mintlify Platform before 2025-11-15 allows rem... |
| CVE-2025-67844 | MEDIUM | 4.3 | 0.4% | Dec 19, 2025 | The GitHub Integration API in Mintlify Platform before 2025-11-15 allows remote attackers to obtain sensitive repository... |
| CVE-2025-67843 | CRITICAL | 9.8 | 1.1% | Dec 19, 2025 | A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15... |
| CVE-2025-67842 | MEDIUM | 5.4 | 0.3% | Dec 19, 2025 | The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HT... |
| CVE-2025-52692 | HIGH | 8.8 | 5.6% | Dec 19, 2025 | Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially craft... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now