2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67074 | MEDIUM | 6.5 | 0.3% | Dec 17, 2025 | A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remot... |
| CVE-2025-67073 | CRITICAL | 9.8 | 0.6% | Dec 17, 2025 | A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remot... |
| CVE-2025-66646 | HIGH | 7.5 | 0.6% | Dec 17, 2025 | RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ... |
| CVE-2025-66397 | HIGH | 8.3 | 0.3% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reload... |
| CVE-2025-66396 | HIGH | 7.2 | 0.3% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in th... |
| CVE-2025-65233 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ... |
| CVE-2025-34442 | HIGH | 7.5 | 0.7% | Dec 17, 2025 | AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata in... |
| CVE-2025-34441 | HIGH | 7.5 | 0.7% | Dec 17, 2025 | AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Response... |
| CVE-2025-34440 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validation of the siteRedire... |
| CVE-2025-34439 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | AVideo versions prior to 20.1 are vulnerable to an open redirect flaw due to missing validation of the cancelUri paramet... |
| CVE-2025-34438 | HIGH | 8.1 | 0.3% | Dec 17, 2025 | AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permi... |
| CVE-2025-34437 | HIGH | 8.8 | 0.4% | Dec 17, 2025 | AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The... |
| CVE-2025-34436 | HIGH | 8.8 | 0.4% | Dec 17, 2025 | AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due... |
| CVE-2025-34435 | MEDIUM | 6.5 | 0.3% | Dec 17, 2025 | AVideo versions prior to 20.1 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated... |
| CVE-2025-34434 | CRITICAL | 9.1 | 0.4% | Dec 17, 2025 | AVideo versions prior to 20.1 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and dele... |
| CVE-2025-14760 | MEDIUM | 6 | 0.1% | Dec 17, 2025 | Missing cryptographic key commitment in the AWS SDK for C++ may allow a user with write access to the S3 bucket to intro... |
| CVE-2025-14759 | MEDIUM | 6 | 0.1% | Dec 17, 2025 | Missing cryptographic key commitment in the Amazon S3 Encryption Client for .NET may allow a user with write access to t... |
| CVE-2025-67174 | HIGH | 7.5 | 1.1% | Dec 17, 2025 | A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a ... |
| CVE-2025-67173 | MEDIUM | 6.8 | 0.2% | Dec 17, 2025 | A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrar... |
| CVE-2025-67171 | HIGH | 7.5 | 0.7% | Dec 17, 2025 | Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via d... |
| CVE-2025-67170 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the... |
| CVE-2025-67168 | MEDIUM | 5.3 | 0.1% | Dec 17, 2025 | RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords. |
| CVE-2025-66953 | HIGH | 8.8 | 0.3% | Dec 17, 2025 | CSRF vulnerability in narda miteq Uplink Power Contril Unit UPC2 v.1.17 allows a remote attacker to execute arbitrary co... |
| CVE-2025-66395 | HIGH | 8.8 | 0.3% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in th... |
| CVE-2025-62521 | CRITICAL | 9.8 | 4.2% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code executio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now