2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66388 | MEDIUM | 6.5 | 0.4% | Dec 15, 2025 | A vulnerability in Apache Airflow allowed authenticated UI users to view secret values in rendered templates due to secr... |
| CVE-2025-37732 | MEDIUM | 5.4 | 0.2% | Dec 15, 2025 | Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated us... |
| CVE-2025-37731 | HIGH | 7.4 | 0.2% | Dec 15, 2025 | Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica... |
| CVE-2025-14714 | MEDIUM | 6.5 | 0.1% | Dec 15, 2025 | An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the T... |
| CVE-2025-11670 | MEDIUM | 4.3 | 0.4% | Dec 15, 2025 | Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is e... |
| CVE-2025-14711 | CRITICAL | 9.8 | 0.4% | Dec 15, 2025 | A flaw has been found in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This vulnerability a... |
| CVE-2025-14710 | CRITICAL | 9.8 | 0.4% | Dec 15, 2025 | A vulnerability was detected in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This affects ... |
| CVE-2025-14709 | CRITICAL | 9.8 | 5.2% | Dec 15, 2025 | A security vulnerability has been detected in Shiguangwu sgwbox N3 2.0.25. Affected by this issue is some unknown functi... |
| CVE-2025-14708 | HIGH | 7.5 | 5.7% | Dec 15, 2025 | A weakness has been identified in Shiguangwu sgwbox N3 2.0.25. Affected by this vulnerability is an unknown functionalit... |
| CVE-2025-14023 | MEDIUM | 4.3 | 0.1% | Dec 15, 2025 | LINE client for iOS prior to 15.19 allows UI spoofing due to inconsistencies between the navigation state and the in-app... |
| CVE-2025-14022 | MEDIUM | 6.8 | 0.2% | Dec 15, 2025 | LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an ... |
| CVE-2025-14021 | MEDIUM | 4.3 | 0.2% | Dec 15, 2025 | The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could all... |
| CVE-2025-14020 | MEDIUM | 4.3 | 0.1% | Dec 15, 2025 | LINE client for Android versions prior to 14.20 contains a UI spoofing vulnerability in the in-app browser where the ful... |
| CVE-2025-14019 | MEDIUM | 4.7 | 0.1% | Dec 15, 2025 | LINE client for Android versions from 13.8 to 15.5 is vulnerable to UI spoofing in the in-app browser where a specific l... |
| CVE-2025-14712 | HIGH | 8.7 | 0.3% | Dec 15, 2025 | Student Learning Assessment and Support System developed by JHENG GAO has a Exposure of Sensitive Information vulnerabil... |
| CVE-2025-14707 | CRITICAL | 9.8 | 16.5% | Dec 15, 2025 | A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25. Affected is an unknown function of the file /usr/sbi... |
| CVE-2025-14706 | CRITICAL | 9.8 | 16.5% | Dec 15, 2025 | A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25. This impacts an unknown function of the file /usr/sbin/ht... |
| CVE-2025-14549 | HIGH | 8.1 | 0.3% | Dec 15, 2025 | In the Eclipse OMR compiler component, since release 0.7.0, an optimization enabled for Eclipse OpenJ9 consumers of OMR ... |
| CVE-2025-13355 | HIGH | 7.1 | 0.1% | Dec 15, 2025 | The URL Shortify WordPress plugin before 1.11.4 does not sanitise and escape a parameter before outputting it back in t... |
| CVE-2025-12684 | HIGH | 7.1 | 0.1% | Dec 15, 2025 | The URL Shortify WordPress plugin before 1.11.3 does not sanitize and escape a parameter before outputting it back in t... |
| CVE-2025-11363 | MEDIUM | 5.3 | 0.3% | Dec 15, 2025 | The Royal Addons for Elementor WordPress plugin before 1.7.1037 does not have proper authorisation, allowing unauthenti... |
| CVE-2025-14705 | CRITICAL | 9.8 | 14.6% | Dec 15, 2025 | A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25. This affects an unknown function of the component SHARESE... |
| CVE-2025-14704 | CRITICAL | 9.8 | 11.0% | Dec 15, 2025 | A vulnerability was found in Shiguangwu sgwbox N3 2.0.25. The impacted element is an unknown function of the file /eshel... |
| CVE-2025-67907 | — | — | — | Dec 15, 2025 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-67906. Reason: This candidate is a reservation d... |
| CVE-2025-67906 | CRITICAL | 9 | 0.3% | Dec 15, 2025 | In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now