2025 CVE Vulnerabilities
45,170 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34442 | HIGH | 7.5 | 0.7% | Dec 17, 2025 | AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata in... |
| CVE-2025-34441 | HIGH | 7.5 | 0.7% | Dec 17, 2025 | AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Response... |
| CVE-2025-34440 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validation of the siteRedire... |
| CVE-2025-34439 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | AVideo versions prior to 20.1 are vulnerable to an open redirect flaw due to missing validation of the cancelUri paramet... |
| CVE-2025-34438 | HIGH | 8.1 | 0.2% | Dec 17, 2025 | AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permi... |
| CVE-2025-34437 | HIGH | 8.8 | 0.4% | Dec 17, 2025 | AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The... |
| CVE-2025-34436 | HIGH | 8.8 | 0.4% | Dec 17, 2025 | AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due... |
| CVE-2025-34435 | MEDIUM | 6.5 | 0.3% | Dec 17, 2025 | AVideo versions prior to 20.1 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated... |
| CVE-2025-34434 | CRITICAL | 9.1 | 0.4% | Dec 17, 2025 | AVideo versions prior to 20.1 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and dele... |
| CVE-2025-14760 | MEDIUM | 6 | 0.1% | Dec 17, 2025 | Missing cryptographic key commitment in the AWS SDK for C++ may allow a user with write access to the S3 bucket to intro... |
| CVE-2025-14759 | MEDIUM | 6 | 0.1% | Dec 17, 2025 | Missing cryptographic key commitment in the Amazon S3 Encryption Client for .NET may allow a user with write access to t... |
| CVE-2025-67174 | HIGH | 7.5 | 1.1% | Dec 17, 2025 | A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a ... |
| CVE-2025-67173 | MEDIUM | 6.8 | 0.2% | Dec 17, 2025 | A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrar... |
| CVE-2025-67171 | HIGH | 7.5 | 0.7% | Dec 17, 2025 | Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via d... |
| CVE-2025-67170 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the... |
| CVE-2025-67168 | MEDIUM | 5.3 | 0.1% | Dec 17, 2025 | RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords. |
| CVE-2025-66953 | HIGH | 8.8 | 0.3% | Dec 17, 2025 | CSRF vulnerability in narda miteq Uplink Power Contril Unit UPC2 v.1.17 allows a remote attacker to execute arbitrary co... |
| CVE-2025-66395 | HIGH | 8.8 | 0.3% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in th... |
| CVE-2025-62521 | CRITICAL | 9.8 | 4.2% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code executio... |
| CVE-2025-14828 | — | — | — | Dec 17, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2025-14081 | MEDIUM | 4.3 | 0.3% | Dec 17, 2025 | The Ultimate Member plugin for WordPress is vulnerable to Profile Privacy Setting Bypass in all versions up to, and incl... |
| CVE-2025-13537 | MEDIUM | 6.4 | 0.2% | Dec 17, 2025 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to multiple Stored Cross-Site Scri... |
| CVE-2025-13326 | LOW | 3.9 | 0.1% | Dec 17, 2025 | Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged f... |
| CVE-2025-13324 | LOW | 3.7 | 0.2% | Dec 17, 2025 | Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite to... |
| CVE-2025-13321 | LOW | 3.3 | 0.1% | Dec 17, 2025 | Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on ser... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now