2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63390 | MEDIUM | 5.3 | 0.5% | Dec 18, 2025 | An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fa... |
| CVE-2025-63389 | CRITICAL | 9.8 | 0.6% | Dec 18, 2025 | A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and includ... |
| CVE-2025-63388 | CRITICAL | 9.1 | 0.2% | Dec 18, 2025 | A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-f... |
| CVE-2025-63386 | CRITICAL | 9.1 | 0.2% | Dec 18, 2025 | A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup en... |
| CVE-2025-14878 | CRITICAL | 9.8 | 0.8% | Dec 18, 2025 | A security flaw has been discovered in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/wirele... |
| CVE-2025-14877 | CRITICAL | 9.8 | 0.3% | Dec 18, 2025 | A vulnerability was identified in Campcodes Supplier Management System 1.0. This affects an unknown function of the file... |
| CVE-2025-14823 | MEDIUM | 5.3 | 0.1% | Dec 18, 2025 | In deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure... |
| CVE-2025-9787 | MEDIUM | 6.1 | 1.1% | Dec 18, 2025 | Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulne... |
| CVE-2025-7358 | CRITICAL | 9.8 | 0.3% | Dec 18, 2025 | Use of Hard-coded Credentials vulnerability in Utarit Informatics Services Inc. SoliClub allows Authentication Abuse. T... |
| CVE-2025-7047 | MEDIUM | 5.4 | 0.1% | Dec 18, 2025 | Missing Authorization vulnerability in Utarit Informatics Services Inc. SoliClub allows Privilege Abuse. This issue aff... |
| CVE-2025-68325 | — | — | 0.2% | Dec 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_cake: Fix incorrect qlen reduction i... |
| CVE-2025-68324 | — | — | 0.2% | Dec 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: imm: Fix use-after-free bug caused by unfinis... |
| CVE-2025-68323 | — | — | 0.2% | Dec 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: fix use-after-free caused by uec-... |
| CVE-2025-65011 | HIGH | 7.1 | 0.2% | Dec 18, 2025 | In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) an unauthorised user can view configuration files by d... |
| CVE-2025-65010 | HIGH | 7.1 | 0.2% | Dec 18, 2025 | WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) is vulnerable to Broken Access Control in initial configu... |
| CVE-2025-65009 | HIGH | 7.1 | 0.2% | Dec 18, 2025 | In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) admin password is stored in configuration file as plai... |
| CVE-2025-65008 | CRITICAL | 9.4 | 2.7% | Dec 18, 2025 | In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of validation in the langGet parameter in ... |
| CVE-2025-65007 | HIGH | 8.7 | 0.3% | Dec 18, 2025 | In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of authentication in the configuration cha... |
| CVE-2025-64469 | HIGH | 7.8 | 0.2% | Dec 18, 2025 | There is a stack-based buffer overflow vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corr... |
| CVE-2025-64468 | HIGH | 8.5 | 0.1% | Dec 18, 2025 | There is a use-after-free vulnerability in sentry!sentry_span_set_data() when parsing a corrupted VI file. This vulnera... |
| CVE-2025-64467 | HIGH | 7.8 | 0.2% | Dec 18, 2025 | There is an out of bounds read vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corrupted VI... |
| CVE-2025-64466 | HIGH | 8.5 | 0.1% | Dec 18, 2025 | There is an out of bounds read vulnerability in NI LabVIEW in lvre!ExecPostedProcRecPost() when parsing a corrupted VI f... |
| CVE-2025-64465 | HIGH | 8.5 | 0.1% | Dec 18, 2025 | There is an out of bounds read vulnerability in NI LabVIEW in lvre!DataSizeTDR() when parsing a corrupted VI file. This... |
| CVE-2025-64464 | HIGH | 8.5 | 0.1% | Dec 18, 2025 | There is an out of bounds read vulnerability in NI LabVIEW in lvre!VisaWriteFromFile() when parsing a corrupted VI file.... |
| CVE-2025-64463 | HIGH | 8.5 | 0.1% | Dec 18, 2025 | There is an out of bounds read vulnerability in NI LabVIEW in LVResource::DetachResource() when parsing a corrupted VI f... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now