2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66402 | MEDIUM | 6.5 | 0.3% | Dec 16, 2025 | Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025... |
| CVE-2025-58173 | HIGH | 8.8 | 0.6% | Dec 16, 2025 | FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1.27.0, using a path traversal inside the `lan... |
| CVE-2025-14731 | HIGH | 7.2 | 0.4% | Dec 16, 2025 | A weakness has been identified in CTCMS Content Management System up to 2.1.2. This affects an unknown function in the l... |
| CVE-2025-14593 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulne... |
| CVE-2025-10900 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulne... |
| CVE-2025-10899 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulne... |
| CVE-2025-10898 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulne... |
| CVE-2025-10889 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force a Memory corruption vulnera... |
| CVE-2025-10888 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulne... |
| CVE-2025-10887 | HIGH | 7.8 | 0.1% | Dec 16, 2025 | A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force a Memory corruption vulnerabi... |
| CVE-2025-10886 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force a Memory corruption vulnerabi... |
| CVE-2025-10884 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | AA maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vul... |
| CVE-2025-10883 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read v... |
| CVE-2025-10882 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | AA maliciously crafted X_T file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnera... |
| CVE-2025-10881 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vu... |
| CVE-2025-9122 | MEDIUM | 5.3 | 0.2% | Dec 15, 2025 | Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, includi... |
| CVE-2025-9121 | HIGH | 8.8 | 0.4% | Dec 15, 2025 | Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and... |
| CVE-2025-14730 | HIGH | 7.2 | 0.4% | Dec 15, 2025 | A security flaw has been discovered in CTCMS Content Management System up to 2.1.2. The impacted element is an unknown f... |
| CVE-2025-14729 | HIGH | 7.2 | 0.4% | Dec 15, 2025 | A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected element is the function Save... |
| CVE-2025-64725 | CRITICAL | 9.8 | 0.3% | Dec 15, 2025 | Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a... |
| CVE-2025-59947 | CRITICAL | 9 | 0.3% | Dec 15, 2025 | NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBL... |
| CVE-2025-55895 | CRITICAL | 9.1 | 0.3% | Dec 15, 2025 | TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to I... |
| CVE-2025-14722 | LOW | 2.4 | 0.2% | Dec 15, 2025 | A vulnerability was determined in vion707 DMadmin up to 3403cafdb42537a648c30bf8cbc8148ec60437d1. This impacts the funct... |
| CVE-2025-67809 | MEDIUM | 4.7 | 0.2% | Dec 15, 2025 | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present i... |
| CVE-2025-55703 | LOW | 3.3 | 0.1% | Dec 15, 2025 | An error-based SQL injection vulnerability exists in the Sunbird Power IQ 9.2.0 API. The vulnerability is due to an outd... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now