2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9121 | HIGH | 8.8 | 0.4% | Dec 15, 2025 | Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and... |
| CVE-2025-14730 | HIGH | 7.2 | 0.4% | Dec 15, 2025 | A security flaw has been discovered in CTCMS Content Management System up to 2.1.2. The impacted element is an unknown f... |
| CVE-2025-14729 | HIGH | 7.2 | 0.4% | Dec 15, 2025 | A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected element is the function Save... |
| CVE-2025-64725 | CRITICAL | 9.8 | 0.3% | Dec 15, 2025 | Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a... |
| CVE-2025-59947 | CRITICAL | 9 | 0.3% | Dec 15, 2025 | NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBL... |
| CVE-2025-55895 | CRITICAL | 9.1 | 0.3% | Dec 15, 2025 | TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to I... |
| CVE-2025-14722 | LOW | 2.4 | 0.2% | Dec 15, 2025 | A vulnerability was determined in vion707 DMadmin up to 3403cafdb42537a648c30bf8cbc8148ec60437d1. This impacts the funct... |
| CVE-2025-67809 | MEDIUM | 4.7 | 0.2% | Dec 15, 2025 | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present i... |
| CVE-2025-55703 | LOW | 3.3 | 0.1% | Dec 15, 2025 | An error-based SQL injection vulnerability exists in the Sunbird Power IQ 9.2.0 API. The vulnerability is due to an outd... |
| CVE-2025-36360 | MEDIUM | 5 | 0.2% | Dec 15, 2025 | IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM De... |
| CVE-2025-14503 | HIGH | 8.6 | 0.4% | Dec 15, 2025 | An overly-permissive IAM trust policy in the Harmonix on AWS framework may allow IAM principals in the same AWS account ... |
| CVE-2025-14148 | MEDIUM | 6.5 | 0.3% | Dec 15, 2025 | IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration pri... |
| CVE-2025-13489 | MEDIUM | 5.9 | 0.2% | Dec 15, 2025 | IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 IBM DevOps Deploy transmits data in clear text that could allow an attac... |
| CVE-2025-12035 | MEDIUM | 6.5 | 0.2% | Dec 15, 2025 | An integer overflow condition exists in Bluetooth Host stack, within the bt_br_acl_recv routine a critical path for proc... |
| CVE-2025-65835 | MEDIUM | 6.2 | 0.3% | Dec 15, 2025 | The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an export... |
| CVE-2025-65213 | CRITICAL | 9.8 | 0.6% | Dec 15, 2025 | MooreThreads torch_musa through all versions contains an unsafe deserialization vulnerability in torch_musa.utils.compar... |
| CVE-2025-65176 | HIGH | 7.5 | 0.4% | Dec 15, 2025 | An issue was discovered in Dynatrace OneAgent before 1.325.47. When attempting to access a remote network share from a m... |
| CVE-2025-51962 | MEDIUM | 6.1 | 0.2% | Dec 15, 2025 | A HTML Injection vulnerability in the comment section of the project page in MicroStudio 24.01.29 allows remote attacker... |
| CVE-2025-66440 | HIGH | 8.8 | 0.3% | Dec 15, 2025 | An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext/acc... |
| CVE-2025-66439 | HIGH | 8.8 | 0.3% | Dec 15, 2025 | An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext.acc... |
| CVE-2025-66438 | HIGH | 8.8 | 0.4% | Dec 15, 2025 | A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format renderin... |
| CVE-2025-66437 | HIGH | 8.8 | 0.5% | Dec 15, 2025 | An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext throug... |
| CVE-2025-66436 | MEDIUM | 4.3 | 0.3% | Dec 15, 2025 | An SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions method of Frappe ERPNext t... |
| CVE-2025-14038 | HIGH | 7 | 0.2% | Dec 15, 2025 | EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. Th... |
| CVE-2025-66435 | MEDIUM | 4.3 | 0.3% | Dec 15, 2025 | An SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method of Frappe ERPNext thro... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now