2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49363 | HIGH | 8.1 | 0.6% | Dec 18, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49362 | HIGH | 8.1 | 0.6% | Dec 18, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49361 | HIGH | 8.1 | 0.5% | Dec 18, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49360 | HIGH | 8.1 | 0.5% | Dec 18, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49359 | HIGH | 8.1 | 0.6% | Dec 18, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49041 | MEDIUM | 6.5 | 0.3% | Dec 18, 2025 | Missing Authorization vulnerability in The African Boss Get Cash get-cash allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-14318 | MEDIUM | 4.3 | 0.3% | Dec 18, 2025 | Improper access checks in M-Files Server before 25.12.15491.7 allows users to download files through M-Files Web using W... |
| CVE-2025-14314 | HIGH | 8.5 | 0.3% | Dec 18, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roxnor PopupKit po... |
| CVE-2025-13498 | MEDIUM | 4.3 | 0.4% | Dec 18, 2025 | The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions ... |
| CVE-2025-12976 | MEDIUM | 6.4 | 0.4% | Dec 18, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2025-10019 | MEDIUM | 6.5 | 0.4% | Dec 18, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in codepeople Contact Form Email contact-form-to-email al... |
| CVE-2025-68463 | MEDIUM | 4.9 | 0.3% | Dec 18, 2025 | Bio.Entrez in Biopython through 186 allows doctype XXE. |
| CVE-2025-68462 | LOW | 3.2 | 0.1% | Dec 18, 2025 | Freedombox before 25.17.1 does not set proper permissions for the backups-data directory, allowing the reading of dump f... |
| CVE-2025-68459 | HIGH | 7.2 | 1.4% | Dec 18, 2025 | RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co., Ltd. contain an OS command injec... |
| CVE-2025-47387 | HIGH | 7.8 | 0.1% | Dec 18, 2025 | Memory Corruption when processing IOCTLs for JPEG data without verification. |
| CVE-2025-47382 | HIGH | 7.8 | 0.1% | Dec 18, 2025 | Memory corruption while loading an invalid firmware in boot loader. |
| CVE-2025-47372 | HIGH | 8.4 | 0.1% | Dec 18, 2025 | Memory Corruption when a corrupted ELF image with an oversized file size is read into a buffer without authentication. |
| CVE-2025-47350 | HIGH | 7.8 | 0.1% | Dec 18, 2025 | Memory corruption while handling concurrent memory mapping and unmapping requests from a user-space application. |
| CVE-2025-47325 | MEDIUM | 5.5 | 0.1% | Dec 18, 2025 | Information disclosure while processing system calls with invalid parameters. |
| CVE-2025-47323 | HIGH | 7.8 | 0.1% | Dec 18, 2025 | Memory corruption while routing GPR packets between user and root when handling large data packet. |
| CVE-2025-47322 | HIGH | 7.8 | 0.1% | Dec 18, 2025 | Memory corruption while handling IOCTL calls to set mode. |
| CVE-2025-47321 | HIGH | 7.8 | 0.1% | Dec 18, 2025 | Memory corruption while copying packets received from unix clients. |
| CVE-2025-47320 | HIGH | 7.8 | 0.1% | Dec 18, 2025 | Memory corruption while processing MFC channel configuration during music playback. |
| CVE-2025-47319 | MEDIUM | 6.7 | 0.1% | Dec 18, 2025 | Information disclosure while exposing internal TA-to-TA communication APIs to HLOS |
| CVE-2025-27063 | HIGH | 7.8 | 0.1% | Dec 18, 2025 | Memory corruption during video playback when video session open fails with time out error. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now