2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68270 | CRITICAL | 9.9 | 0.3% | Dec 16, 2025 | The Open edX Platform is a learning management platform. Prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, Cours... |
| CVE-2025-68156 | HIGH | 7.5 | 0.4% | Dec 16, 2025 | Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in E... |
| CVE-2025-68155 | HIGH | 7.5 | 0.6% | Dec 16, 2025 | @vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_find... |
| CVE-2025-68154 | HIGH | 8.1 | 13.0% | Dec 16, 2025 | systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` funct... |
| CVE-2025-68150 | MEDIUM | 6.5 | 0.3% | Dec 16, 2025 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2025-68146 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTO... |
| CVE-2025-65593 | HIGH | 8.8 | 0.3% | Dec 16, 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality. |
| CVE-2025-65592 | MEDIUM | 6.1 | 0.3% | Dec 16, 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloa... |
| CVE-2025-65591 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Currencies functionality. |
| CVE-2025-65590 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Blog posts functionality in the Content Managemen... |
| CVE-2025-14553 | HIGH | 7 | 0.2% | Dec 16, 2025 | Exposure of password hashes through an unauthenticated API response in TP-Link Tapo app on iOS and Android for Tapo came... |
| CVE-2025-68142 | MEDIUM | 5.3 | 0.4% | Dec 16, 2025 | PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. Versions prior to 10.16.1 have a R... |
| CVE-2025-65589 | MEDIUM | 6.1 | 0.4% | Dec 16, 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Attributes functionality. |
| CVE-2025-65581 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improp... |
| CVE-2025-62864 | CRITICAL | 9.8 | 0.4% | Dec 16, 2025 | Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.... |
| CVE-2025-62863 | CRITICAL | 9.8 | 0.4% | Dec 16, 2025 | Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.... |
| CVE-2025-52196 | HIGH | 7.5 | 0.3% | Dec 16, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Ctera Portal 8.1.x (8.1.1417.24) allows remote attackers to induce t... |
| CVE-2025-46296 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privile... |
| CVE-2025-46295 | CRITICAL | 9.8 | 0.9% | Dec 16, 2025 | Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications pass... |
| CVE-2025-46294 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumerat... |
| CVE-2025-33235 | HIGH | 7 | 0.1% | Dec 16, 2025 | NVIDIA Resiliency Extension for Linux contains a vulnerability in the checkpointing core, where an attacker may cause a ... |
| CVE-2025-33226 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | NVIDIA NeMo Framework for all platforms contains a vulnerability where malicious data created by an attacker may cause a... |
| CVE-2025-33225 | HIGH | 8.4 | 0.3% | Dec 16, 2025 | NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predict... |
| CVE-2025-33212 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | NVIDIA NeMo Framework contains a vulnerability in model loading that could allow an attacker to exploit improper control... |
| CVE-2025-33210 | CRITICAL | 9 | 0.5% | Dec 16, 2025 | NVIDIA Isaac Lab contains a deserialization vulnerability. A successful exploit of this vulnerability might lead to cod... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now