2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66499 | HIGH | 7.8 | 0.3% | Dec 19, 2025 | A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially craft... |
| CVE-2025-66498 | HIGH | 7.8 | 0.2% | Dec 19, 2025 | A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds ch... |
| CVE-2025-66497 | HIGH | 7.8 | 0.2% | Dec 19, 2025 | A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds ch... |
| CVE-2025-66496 | HIGH | 7.8 | 0.2% | Dec 19, 2025 | A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds ch... |
| CVE-2025-66495 | HIGH | 7.8 | 0.3% | Dec 19, 2025 | A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1... |
| CVE-2025-66494 | HIGH | 7.8 | 0.3% | Dec 19, 2025 | A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on... |
| CVE-2025-66493 | HIGH | 7.8 | 0.3% | Dec 19, 2025 | A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,... |
| CVE-2025-66174 | MEDIUM | 6.8 | 0.3% | Dec 19, 2025 | There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of ... |
| CVE-2025-66173 | MEDIUM | 6.2 | 0.2% | Dec 19, 2025 | There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of auth... |
| CVE-2025-14449 | MEDIUM | 6.4 | 0.2% | Dec 19, 2025 | The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's babe-search-fo... |
| CVE-2025-14267 | MEDIUM | 4.9 | 0.4% | Dec 19, 2025 | Incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server allows d... |
| CVE-2025-13999 | HIGH | 7.2 | 0.2% | Dec 19, 2025 | The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server-S... |
| CVE-2025-13754 | MEDIUM | 5.3 | 0.3% | Dec 19, 2025 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to Sensitive ... |
| CVE-2025-13008 | HIGH | 8.6 | 0.5% | Dec 19, 2025 | An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and ... |
| CVE-2025-13307 | HIGH | 7.2 | 0.5% | Dec 19, 2025 | The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic.... |
| CVE-2025-14546 | MEDIUM | 6.3 | 0.4% | Dec 19, 2025 | Versions of the package fastapi-sso before 0.19.0 are vulnerable to Cross-site Request Forgery (CSRF) due to the imprope... |
| CVE-2025-68491 | — | — | — | Dec 19, 2025 | Rejected reason: Not used |
| CVE-2025-68490 | — | — | — | Dec 19, 2025 | Rejected reason: Not used |
| CVE-2025-68489 | — | — | — | Dec 19, 2025 | Rejected reason: Not used |
| CVE-2025-68488 | — | — | — | Dec 19, 2025 | Rejected reason: Not used |
| CVE-2025-68487 | — | — | — | Dec 19, 2025 | Rejected reason: Not used |
| CVE-2025-68486 | — | — | — | Dec 19, 2025 | Rejected reason: Not used |
| CVE-2025-68485 | — | — | — | Dec 19, 2025 | Rejected reason: Not used |
| CVE-2025-68484 | — | — | — | Dec 19, 2025 | Rejected reason: Not used |
| CVE-2025-68483 | — | — | — | Dec 19, 2025 | Rejected reason: Not used |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now