2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68461 | MEDIUM | 6.1 | 19.8% | Dec 18, 2025 | Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the ani... |
| CVE-2025-68460 | HIGH | 7.5 | 0.2% | Dec 18, 2025 | Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML sty... |
| CVE-2025-12885 | MEDIUM | 6.4 | 0.2% | Dec 18, 2025 | The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-... |
| CVE-2025-14856 | HIGH | 8.8 | 0.4% | Dec 18, 2025 | A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function o... |
| CVE-2025-14841 | LOW | 3.3 | 0.1% | Dec 18, 2025 | A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted element is the function DcmQueryRetrieveIndexDatabaseHand... |
| CVE-2025-14837 | HIGH | 7.2 | 0.4% | Dec 18, 2025 | A vulnerability has been found in ZZCMS 2025. Affected by this issue is the function stripfxg of the file /admin/sitecon... |
| CVE-2025-14202 | HIGH | 8.2 | 0.3% | Dec 18, 2025 | A vulnerability in the file upload at bookmark + asset rendering pipeline allows an attacker to upload a malicious SVG f... |
| CVE-2025-68435 | CRITICAL | 9.1 | 0.4% | Dec 17, 2025 | Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulne... |
| CVE-2025-68434 | HIGH | 8.8 | 0.2% | Dec 17, 2025 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram... |
| CVE-2025-68433 | HIGH | 7.3 | 0.3% | Dec 17, 2025 | Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Mo... |
| CVE-2025-68432 | HIGH | 7.3 | 0.3% | Dec 17, 2025 | Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads La... |
| CVE-2025-68429 | MEDIUM | 5.3 | 0.2% | Dec 17, 2025 | Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present ... |
| CVE-2025-68147 | HIGH | 8.1 | 0.3% | Dec 17, 2025 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram... |
| CVE-2025-68145 | CRITICAL | 9.1 | 7.0% | Dec 17, 2025 | In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operat... |
| CVE-2025-68144 | HIGH | 7.1 | 7.3% | Dec 17, 2025 | In mcp-server-git versions prior to 2025.12.17, the git_diff and git_checkout functions passed user-controlled arguments... |
| CVE-2025-68143 | HIGH | 8.8 | 8.1% | Dec 17, 2025 | Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp... |
| CVE-2025-66029 | HIGH | 7.6 | 0.2% | Dec 17, 2025 | Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensiti... |
| CVE-2025-14836 | LOW | 2.7 | 0.2% | Dec 17, 2025 | A flaw has been found in ZZCMS 2025. Affected by this vulnerability is an unknown functionality of the file /reg/user_sa... |
| CVE-2025-14834 | HIGH | 8.8 | 0.3% | Dec 17, 2025 | A weakness has been identified in code-projects Simple Stock System 1.0. This affects an unknown function of the file /c... |
| CVE-2025-14833 | CRITICAL | 9.8 | 0.3% | Dec 17, 2025 | A security flaw has been discovered in code-projects Online Appointment Booking System 1.0. The impacted element is an u... |
| CVE-2025-14319 | — | — | — | Dec 17, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-14268 | — | — | — | Dec 17, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-68401 | MEDIUM | 4.8 | 0.2% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Prior to version 6.0.0, the application stores user-supplied HTML/... |
| CVE-2025-68400 | HIGH | 8.8 | 0.3% | Dec 17, 2025 | ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in the legacy endpoint `/Repo... |
| CVE-2025-68399 | MEDIUM | 5.4 | 0.2% | Dec 17, 2025 | ChurchCRM is an open-source church management system. In versions prior to 6.5.4, there is a Stored Cross-Site Scripting... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now