2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68741 | CRITICAL | 9.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix improper freeing of purex item ... |
| CVE-2025-68726 | CRITICAL | 9.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: crypto: aead - Fix reqsize handling Commit afddce1... |
| CVE-2025-68359 | CRITICAL | 9.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double free of qgroup record after failu... |
| CVE-2025-13773 | CRITICAL | 9.8 | 3.2% | Dec 24, 2025 | The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all ve... |
| CVE-2025-68669 | CRITICAL | 9.6 | 0.4% | Dec 23, 2025 | 5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. In versions 0.15.2... |
| CVE-2025-68667 | CRITICAL | 9.9 | 0.5% | Dec 23, 2025 | Conduit is a chat server powered by Matrix. A vulnerability that affects a number of Conduit-derived homeservers allows ... |
| CVE-2025-68665 | CRITICAL | 9.1 | 0.7% | Dec 23, 2025 | LangChain is a framework for building LLM-powered applications. Prior to @langchain/core versions 0.3.80 and 1.1.8, and ... |
| CVE-2025-15049 | CRITICAL | 9.8 | 0.3% | Dec 23, 2025 | A vulnerability was identified in code-projects Online Farm System 1.0. Affected is an unknown function of the file /add... |
| CVE-2025-15048 | CRITICAL | 9.8 | 11.3% | Dec 23, 2025 | A vulnerability was determined in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/CheckTools ... |
| CVE-2025-15047 | CRITICAL | 9.8 | 1.1% | Dec 23, 2025 | A vulnerability was found in Tenda WH450 1.0.0.18. This affects an unknown function of the file /goform/PPTPDClient of t... |
| CVE-2025-15046 | CRITICAL | 9.8 | 1.0% | Dec 23, 2025 | A vulnerability has been found in Tenda WH450 1.0.0.18. The impacted element is an unknown function of the file /goform/... |
| CVE-2025-14500 | CRITICAL | 9.8 | 1.4% | Dec 23, 2025 | IceWarp14 X-File-Operation Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attac... |
| CVE-2025-15045 | CRITICAL | 9.8 | 1.0% | Dec 23, 2025 | A flaw has been found in Tenda WH450 1.0.0.18. The affected element is an unknown function of the file /goform/Natlimit ... |
| CVE-2025-15044 | CRITICAL | 9.8 | 1.0% | Dec 23, 2025 | A vulnerability was detected in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/NatStaticSetti... |
| CVE-2025-14931 | CRITICAL | 10 | 0.8% | Dec 23, 2025 | Hugging Face smolagents Remote Python Executor Deserialization of Untrusted Data Remote Code Execution Vulnerability. Th... |
| CVE-2025-65354 | CRITICAL | 9.8 | 0.5% | Dec 23, 2025 | Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injecti... |
| CVE-2025-51511 | CRITICAL | 9.8 | 0.3% | Dec 23, 2025 | Cadmium CMS v.0.4.9 has a background arbitrary file upload vulnerability in /admin/content/filemanager/uploads. |
| CVE-2025-33224 | CRITICAL | 9.8 | 0.7% | Dec 23, 2025 | NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges.... |
| CVE-2025-33223 | CRITICAL | 9.8 | 0.6% | Dec 23, 2025 | NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges.... |
| CVE-2025-33222 | CRITICAL | 9.8 | 0.5% | Dec 23, 2025 | NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit a hard-coded credential issue. A succes... |
| CVE-2025-29229 | CRITICAL | 9.8 | 1.1% | Dec 23, 2025 | linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus. |
| CVE-2025-29228 | CRITICAL | 9.8 | 1.1% | Dec 23, 2025 | Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter. |
| CVE-2025-67109 | CRITICAL | 10 | 0.3% | Dec 23, 2025 | Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certifica... |
| CVE-2025-67108 | CRITICAL | 10 | 0.3% | Dec 23, 2025 | eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure commun... |
| CVE-2025-50526 | CRITICAL | 9.8 | 1.0% | Dec 23, 2025 | Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now