2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68275 | MEDIUM | 4.8 | 0.2% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a stored cross-site scripting vulnera... |
| CVE-2025-68129 | HIGH | 7.5 | 0.4% | Dec 17, 2025 | Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the a... |
| CVE-2025-68118 | CRITICAL | 9.1 | 0.2% | Dec 17, 2025 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.20.0, a vulnerability exists in Free... |
| CVE-2025-68114 | CRITICAL | 9.8 | 0.2% | Dec 17, 2025 | Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat... |
| CVE-2025-68112 | HIGH | 8.8 | 0.4% | Dec 17, 2025 | ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability in Churc... |
| CVE-2025-68111 | HIGH | 7.2 | 0.3% | Dec 17, 2025 | ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability exists i... |
| CVE-2025-68110 | HIGH | 8.8 | 0.4% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an er... |
| CVE-2025-68109 | HIGH | 7.2 | 1.5% | Dec 17, 2025 | ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality doe... |
| CVE-2025-67877 | HIGH | 8.8 | 0.3% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a SQL injection vulnerability in the ... |
| CVE-2025-67876 | MEDIUM | 5.4 | 0.2% | Dec 17, 2025 | ChurchCRM is an open-source church management system. A stored cross-site scripting (XSS) vulnerability exists in Church... |
| CVE-2025-67875 | MEDIUM | 5.4 | 0.2% | Dec 17, 2025 | ChurchCRM is an open-source church management system. A privilege escalation vulnerability exists in ChurchCRM prior to ... |
| CVE-2025-67873 | HIGH | 7.8 | 0.2% | Dec 17, 2025 | Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, Skipdata length is not bounds-checked, so a use... |
| CVE-2025-67794 | MEDIUM | 6.1 | 0.1% | Dec 17, 2025 | An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 before 24.2.8, and 25.1 before 25.1.6. Directories and fi... |
| CVE-2025-67791 | CRITICAL | 9.8 | 0.4% | Dec 17, 2025 | An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete co... |
| CVE-2025-14832 | CRITICAL | 9.8 | 0.3% | Dec 17, 2025 | A vulnerability was identified in itsourcecode Online Cake Ordering System 1.0. The affected element is an unknown funct... |
| CVE-2025-67793 | CRITICAL | 9.8 | 0.3% | Dec 17, 2025 | An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "M... |
| CVE-2025-67792 | HIGH | 7.8 | 0.1% | Dec 17, 2025 | An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged ... |
| CVE-2025-67790 | HIGH | 7.5 | 0.3% | Dec 17, 2025 | An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. An unprivileged use... |
| CVE-2025-67789 | MEDIUM | 5.3 | 0.2% | Dec 17, 2025 | An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Authenticated users... |
| CVE-2025-67493 | CRITICAL | 9 | 0.3% | Dec 17, 2025 | Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed privilege e... |
| CVE-2025-66647 | CRITICAL | 9.8 | 0.8% | Dec 17, 2025 | RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ... |
| CVE-2025-59849 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lo... |
| CVE-2025-55254 | MEDIUM | 4.8 | 0.2% | Dec 17, 2025 | Improper management of Path-relative stylesheet import in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.032... |
| CVE-2025-53000 | HIGH | 7.8 | 0.2% | Dec 17, 2025 | The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions... |
| CVE-2025-46292 | MEDIUM | 5.5 | 0.1% | Dec 17, 2025 | This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now