2025 CVE Vulnerabilities
45,327 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68282 | — | — | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: fix use-after-free in usb_gadget_... |
| CVE-2025-68269 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH |
| CVE-2025-68268 | MEDIUM | 6.1 | 0.2% | Dec 16, 2025 | In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page |
| CVE-2025-68267 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token in... |
| CVE-2025-68166 | MEDIUM | 6.1 | 0.2% | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab |
| CVE-2025-68165 | MEDIUM | 6.1 | 3.5% | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup |
| CVE-2025-68164 | LOW | 2.7 | 0.2% | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test |
| CVE-2025-68163 | MEDIUM | 4.8 | 0.2% | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page |
| CVE-2025-68162 | LOW | 2.7 | 0.2% | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration |
| CVE-2025-65427 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | An issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not impleme... |
| CVE-2025-65319 | CRITICAL | 9.1 | 0.5% | Dec 16, 2025 | When using the attachment interaction functionality, Blue Mail 1.140.103 and below saves documents to a file system with... |
| CVE-2025-65318 | CRITICAL | 9.1 | 0.5% | Dec 16, 2025 | When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system witho... |
| CVE-2025-64012 | MEDIUM | 4.3 | 0.3% | Dec 16, 2025 | InvoicePlane commit debb446c is vulnerable to Incorrect Access Control. The invoices/view handler fails to verify owners... |
| CVE-2025-62329 | MEDIUM | 5.6 | 0.2% | Dec 16, 2025 | HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which ma... |
| CVE-2025-14432 | MEDIUM | 4.9 | 0.4% | Dec 16, 2025 | In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC... |
| CVE-2025-10450 | HIGH | 7.5 | 0.2% | Dec 16, 2025 | Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Librar... |
| CVE-2025-68281 | — | — | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: bug fix while parsing mipi-sdca-control... |
| CVE-2025-68266 | — | — | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: bfs: Reconstruct file type when loading from disk ... |
| CVE-2025-68265 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: nvme: fix admin request_queue lifetime The namespa... |
| CVE-2025-68264 | — | — | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: ext4: refresh inline data size before write operati... |
| CVE-2025-68263 | CRITICAL | 9.8 | 0.4% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: ipc: fix use-after-free in ipc_msg_send_requ... |
| CVE-2025-68262 | — | — | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: crypto: zstd - fix double-free in per-CPU stream cl... |
| CVE-2025-68261 | HIGH | 7.5 | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: ext4: add i_data_sem protection in ext4_destroy_inl... |
| CVE-2025-68260 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: rust_binder: fix race condition on death_list Rust... |
| CVE-2025-68259 | — | — | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Don't skip unrelated instruction if INT3/... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now