2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66909 | HIGH | 7.5 | 0.5% | Dec 19, 2025 | Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an image decompression bomb denial of service vulnerabilit... |
| CVE-2025-66908 | MEDIUM | 5.3 | 0.4% | Dec 19, 2025 | Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an improper file type validation vulnerability in the OCR ... |
| CVE-2025-50681 | HIGH | 7.5 | 0.5% | Dec 19, 2025 | igmpproxy 0.4 before commit 2b30c36 allows remote attackers to cause a denial of service (application crash) via a craft... |
| CVE-2025-14952 | CRITICAL | 9.8 | 0.4% | Dec 19, 2025 | A vulnerability was detected in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /... |
| CVE-2025-14951 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | A security vulnerability has been detected in code-projects Scholars Tracking System 1.0. The impacted element is an unk... |
| CVE-2025-14950 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | A weakness has been identified in code-projects Scholars Tracking System 1.0. The affected element is an unknown functio... |
| CVE-2025-1928 | CRITICAL | 9.1 | 0.3% | Dec 19, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Restajet Information Technologies Inc. Online... |
| CVE-2025-14946 | MEDIUM | 4.8 | 0.1% | Dec 19, 2025 | A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Unifor... |
| CVE-2025-14882 | LOW | 3.8 | 0.2% | Dec 19, 2025 | An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intende... |
| CVE-2025-14881 | LOW | 3.8 | 0.2% | Dec 19, 2025 | Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not ... |
| CVE-2025-1927 | HIGH | 7.1 | 0.1% | Dec 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Restajet Information Technologies Inc. Online Food Delivery System al... |
| CVE-2025-1885 | MEDIUM | 5.4 | 0.1% | Dec 19, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Restajet Information Technologies Inc. Online Food ... |
| CVE-2025-14847 | HIGH | 8.7 | 83.0% | Dec 19, 2025 | Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthe... |
| CVE-2025-66524 | HIGH | 8.8 | 0.4% | Dec 19, 2025 | Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Di... |
| CVE-2025-14455 | MEDIUM | 5.4 | 0.3% | Dec 19, 2025 | The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to authorization bypass in all versions up t... |
| CVE-2025-12361 | MEDIUM | 4.3 | 0.2% | Dec 19, 2025 | The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vulne... |
| CVE-2025-14151 | HIGH | 7.2 | 0.4% | Dec 19, 2025 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'outbound_resource' par... |
| CVE-2025-11747 | MEDIUM | 6.4 | 0.3% | Dec 19, 2025 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the colibri_blog_posts sh... |
| CVE-2025-66522 | MEDIUM | 5.4 | 0.1% | Dec 19, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the Digital IDs functionality of the Foxit PDF Editor Cloud ... |
| CVE-2025-66521 | MEDIUM | 5.4 | 0.1% | Dec 19, 2025 | A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Trusted Certificates feature.... |
| CVE-2025-66520 | MEDIUM | 5.4 | 0.1% | Dec 19, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the Portfolio feature of the Foxit PDF Editor cloud (pdfonli... |
| CVE-2025-66519 | MEDIUM | 5.4 | 0.2% | Dec 19, 2025 | A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Layer Import functionality. A... |
| CVE-2025-66502 | MEDIUM | 5.4 | 0.2% | Dec 19, 2025 | A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Page Templates feature. A cra... |
| CVE-2025-66501 | MEDIUM | 5.4 | 0.1% | Dec 19, 2025 | A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Predefined Text feature of th... |
| CVE-2025-66500 | MEDIUM | 5.4 | 0.2% | Dec 19, 2025 | A stored cross-site scripting (XSS) vulnerability exists in webplugins.foxit.com. A postMessage handler fails to validat... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now