2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64462 | HIGH | 7.8 | 0.2% | Dec 18, 2025 | There is an out of bounds read vulnerability in NI LabVIEW in LVResFile::RGetMemFileHandle() when parsing a corrupted VI... |
| CVE-2025-64461 | HIGH | 8.5 | 0.1% | Dec 18, 2025 | There is an out of bounds write vulnerability in NI LabVIEW in mgocre_SH_25_3!RevBL() when parsing a corrupted VI file. ... |
| CVE-2025-63757 | HIGH | 7.5 | 0.3% | Dec 18, 2025 | Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0. |
| CVE-2025-1031 | HIGH | 7.5 | 0.3% | Dec 18, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Utarit Informatics Services Inc. SoliClub allows Funct... |
| CVE-2025-1030 | HIGH | 7.5 | 0.3% | Dec 18, 2025 | Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Utarit Informatics Services Inc. Soli... |
| CVE-2025-1029 | HIGH | 7.5 | 0.2% | Dec 18, 2025 | Use of Hard-coded Credentials vulnerability in Utarit Information Services Inc. SoliClub allows Read Sensitive Constants... |
| CVE-2025-14861 | HIGH | 8.8 | 0.3% | Dec 18, 2025 | Memory safety bugs present in Firefox 146. Some of these bugs showed evidence of memory corruption and we presume that w... |
| CVE-2025-14860 | CRITICAL | 9.8 | 0.3% | Dec 18, 2025 | Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146.0.1. |
| CVE-2025-14744 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, poten... |
| CVE-2025-65000 | MEDIUM | 5.3 | 0.2% | Dec 18, 2025 | SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2... |
| CVE-2025-40898 | HIGH | 8.1 | 0.3% | Dec 18, 2025 | A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validatio... |
| CVE-2025-40893 | MEDIUM | 6.1 | 0.2% | Dec 18, 2025 | A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of netwo... |
| CVE-2025-40892 | HIGH | 8.9 | 0.2% | Dec 18, 2025 | A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an... |
| CVE-2025-40891 | MEDIUM | 4.7 | 0.2% | Dec 18, 2025 | A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper val... |
| CVE-2025-14618 | MEDIUM | 4.3 | 0.2% | Dec 18, 2025 | The Sweet Energy Efficiency plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data du... |
| CVE-2025-14437 | HIGH | 7.5 | 1.9% | Dec 18, 2025 | The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ... |
| CVE-2025-14277 | MEDIUM | 4.3 | 0.3% | Dec 18, 2025 | The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all version... |
| CVE-2025-13110 | MEDIUM | 4.3 | 0.3% | Dec 18, 2025 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Re... |
| CVE-2025-10910 | CRITICAL | 9.3 | 0.4% | Dec 18, 2025 | A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online... |
| CVE-2025-40602 | MEDIUM | 6.6 | 1.9% | Dec 18, 2025 | A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance manageme... |
| CVE-2025-64997 | MEDIUM | 6.5 | 0.2% | Dec 18, 2025 | Insufficient permission validation in Checkmk versions prior to 2.4.0p17 and 2.3.0p42 allow low-privileged users to view... |
| CVE-2025-14364 | HIGH | 8.8 | 0.3% | Dec 18, 2025 | The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized modification of data, loss of data, and privil... |
| CVE-2025-13730 | MEDIUM | 6.4 | 0.2% | Dec 18, 2025 | The OpenID Connect Generic Client plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'op... |
| CVE-2025-13641 | HIGH | 8.8 | 0.7% | Dec 18, 2025 | The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclu... |
| CVE-2025-14874 | HIGH | 7.5 | 0.6% | Dec 18, 2025 | A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now