2025 CVE Vulnerabilities
45,170 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11369 | MEDIUM | 4.3 | 0.3% | Dec 17, 2025 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to unau... |
| CVE-2025-11009 | MEDIUM | 5.1 | 0.1% | Dec 17, 2025 | Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GT Designer3 Version1 (GOT2000) all vers... |
| CVE-2025-53524 | HIGH | 8.4 | 0.2% | Dec 17, 2025 | Fuji Electric Monitouch V-SFT-6 is vulnerable to an out-of-bounds write while processing a specially crafted project fi... |
| CVE-2025-14701 | HIGH | 7.1 | 0.2% | Dec 17, 2025 | An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated... |
| CVE-2025-14700 | CRITICAL | 9.9 | 6.0% | Dec 17, 2025 | An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authentica... |
| CVE-2025-34288 | MEDIUM | 6.7 | 1.8% | Dec 16, 2025 | Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between s... |
| CVE-2025-14766 | HIGH | 8.8 | 2.8% | Dec 16, 2025 | Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exp... |
| CVE-2025-14765 | HIGH | 8.8 | 2.6% | Dec 16, 2025 | Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap ... |
| CVE-2025-68274 | HIGH | 7.5 | 0.5% | Dec 16, 2025 | SIPGO is a library for writing SIP services in the GO language. Starting in version 0.3.0 and prior to version 1.0.0-alp... |
| CVE-2025-64520 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unau... |
| CVE-2025-53619 | CRITICAL | 9.1 | 0.2% | Dec 16, 2025 | An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A ... |
| CVE-2025-53618 | CRITICAL | 9.1 | 0.2% | Dec 16, 2025 | An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A ... |
| CVE-2025-52582 | HIGH | 7.5 | 0.3% | Dec 16, 2025 | An out-of-bounds read vulnerability exists in the Overlay::GrabOverlayFromPixelData functionality of Grassroot DICOM 3.0... |
| CVE-2025-48429 | CRITICAL | 9.1 | 0.3% | Dec 16, 2025 | An out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality of Grassroot DICOM 3.024. A sp... |
| CVE-2025-14466 | MEDIUM | 6.9 | 0.3% | Dec 16, 2025 | A vulnerability in the web interface of the Güralp Fortimus Series, Minimus Series and Certimus Series allows an unauthe... |
| CVE-2025-0852 | — | — | — | Dec 16, 2025 | Rejected reason: Voluntarily withdrawn |
| CVE-2025-8872 | HIGH | 7.1 | 0.3% | Dec 16, 2025 | On affected platforms running Arista EOS with OSPFv3 configured, a specially crafted packet can cause the OSFPv3 process... |
| CVE-2025-65834 | CRITICAL | 9.8 | 0.3% | Dec 16, 2025 | Meltytech Shotcut 25.10.31 is vulnerable to Buffer Overflow. A memory access violation occurs when processing MLT projec... |
| CVE-2025-13532 | MEDIUM | 6.2 | 0.1% | Dec 16, 2025 | Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the sele... |
| CVE-2025-68270 | CRITICAL | 9.9 | 0.3% | Dec 16, 2025 | The Open edX Platform is a learning management platform. Prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, Cours... |
| CVE-2025-68156 | HIGH | 7.5 | 0.4% | Dec 16, 2025 | Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in E... |
| CVE-2025-68155 | HIGH | 7.5 | 0.6% | Dec 16, 2025 | @vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_find... |
| CVE-2025-68154 | HIGH | 8.1 | 12.9% | Dec 16, 2025 | systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` funct... |
| CVE-2025-68150 | MEDIUM | 6.5 | 0.3% | Dec 16, 2025 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2025-68146 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTO... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now