2025 CVE Vulnerabilities
45,170 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13217 | MEDIUM | 6.4 | 0.3% | Dec 17, 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for W... |
| CVE-2025-12689 | MEDIUM | 6.5 | 0.2% | Dec 17, 2025 | Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for p... |
| CVE-2025-67172 | HIGH | 7.2 | 0.8% | Dec 17, 2025 | RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_specia... |
| CVE-2025-66924 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remot... |
| CVE-2025-66923 | HIGH | 7.2 | 0.5% | Dec 17, 2025 | A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remot... |
| CVE-2025-65203 | HIGH | 7.1 | 0.1% | Dec 17, 2025 | KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-e... |
| CVE-2025-67285 | HIGH | 7.3 | 0.2% | Dec 17, 2025 | A SQL injection vulnerability was found in the '/cts/admin/?page=zone' file of ITSourcecode COVID Tracking System Using ... |
| CVE-2025-67165 | CRITICAL | 9.8 | 0.4% | Dec 17, 2025 | An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges. |
| CVE-2025-67164 | CRITICAL | 9.9 | 0.4% | Dec 17, 2025 | An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows att... |
| CVE-2025-66921 | HIGH | 7.2 | 0.5% | Dec 17, 2025 | A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows re... |
| CVE-2025-65855 | MEDIUM | 6.6 | 0.1% | Dec 17, 2025 | The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-... |
| CVE-2025-65185 | LOW | 2.8 | 0.1% | Dec 17, 2025 | There is a username enumeration via local user login in Entrinsik Informer v5.10.1 which allows malicious users to enume... |
| CVE-2025-53919 | HIGH | 7.8 | 0.1% | Dec 17, 2025 | An issue was discovered in the Portrait Dell Color Management application through 3.3.008 for Dell monitors, It creates ... |
| CVE-2025-53398 | HIGH | 7.8 | 0.1% | Dec 17, 2025 | The Portrait Dell Color Management application 3.3.8 for Dell monitors has Insecure Permissions, |
| CVE-2025-26381 | MEDIUM | 6.5 | 0.3% | Dec 17, 2025 | Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to sensitive informati... |
| CVE-2025-20393 | CRITICAL | 10 | 29.1% | Dec 17, 2025 | A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure... |
| CVE-2025-44005 | CRITICAL | 10 | 3.3% | Dec 17, 2025 | An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without ... |
| CVE-2025-43873 | HIGH | 8.7 | 0.3% | Dec 17, 2025 | Successful exploitation of these vulnerabilities could allow an attacker to modify firmware and gain full access to the ... |
| CVE-2025-14727 | HIGH | 8.7 | 0.4% | Dec 17, 2025 | A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software v... |
| CVE-2025-14266 | LOW | 0.6 | 0.2% | Dec 17, 2025 | CSRF in Ercom Cryptobox administration console allows attacker to trigger some actions on behalf of a Cryptobox administ... |
| CVE-2025-62690 | MEDIUM | 6.1 | 0.1% | Dec 17, 2025 | Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to re... |
| CVE-2025-62190 | MEDIUM | 4.3 | 0.1% | Dec 17, 2025 | Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail... |
| CVE-2025-61736 | HIGH | 7.1 | 0.1% | Dec 17, 2025 | Successful exploitation of this vulnerability could result in the product failing to re-establish communication once the... |
| CVE-2025-14097 | HIGH | 7.2 | 0.4% | Dec 17, 2025 | A vulnerability in the application software of multiple Radiometer products may allow remote code execution and unauthor... |
| CVE-2025-14096 | HIGH | 8.4 | 0.1% | Dec 17, 2025 | A vulnerability exists in multiple Radiometer products that allow an attacker with physical access to the analyzer possi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now