2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66434 | HIGH | 8.8 | 0.5% | Dec 15, 2025 | An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext th... |
| CVE-2025-65742 | HIGH | 8.2 | 0.3% | Dec 15, 2025 | An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to... |
| CVE-2025-55901 | MEDIUM | 6.5 | 1.1% | Dec 15, 2025 | TOTOLINK A3300R V17.0.0cu.596_B20250515 is vulnerable to command injection in the function NTPSyncWithHost via the host_... |
| CVE-2025-55893 | MEDIUM | 6.5 | 1.1% | Dec 15, 2025 | TOTOLINK N200RE V9.3.5u.6437_B20230519 is vulnerable to command Injection in setOpModeCfg via hostName. |
| CVE-2025-11393 | HIGH | 8.7 | 0.2% | Dec 15, 2025 | A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of... |
| CVE-2025-66963 | MEDIUM | 5.5 | 0.1% | Dec 15, 2025 | An issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in... |
| CVE-2025-66844 | CRITICAL | 9.1 | 0.2% | Dec 15, 2025 | In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is ... |
| CVE-2025-66843 | MEDIUM | 5.4 | 0.1% | Dec 15, 2025 | grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An... |
| CVE-2025-60786 | HIGH | 8.8 | 0.5% | Dec 15, 2025 | A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arb... |
| CVE-2025-14387 | MEDIUM | 6.4 | 0.2% | Dec 15, 2025 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions ... |
| CVE-2025-13888 | CRITICAL | 9.1 | 0.7% | Dec 15, 2025 | A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system in... |
| CVE-2025-13824 | HIGH | 8.7 | 0.3% | Dec 15, 2025 | A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard f... |
| CVE-2025-13823 | HIGH | 7.1 | 0.2% | Dec 15, 2025 | A security issue was found in the IPv6 stack in the Micro850 and Micro870 controllers when the controllers received mult... |
| CVE-2025-34412 | — | — | — | Dec 15, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it identified a vulne... |
| CVE-2025-34411 | — | — | — | Dec 15, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it identified a vulne... |
| CVE-2025-34181 | HIGH | 8.7 | 0.9% | Dec 15, 2025 | NetSupport Manager < 14.12.0001 contains an arbitrary file write vulnerability in its Connectivity Server/Gateway PUTFIL... |
| CVE-2025-34180 | HIGH | 8.4 | 0.2% | Dec 15, 2025 | NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and ... |
| CVE-2025-34179 | HIGH | 8.7 | 0.3% | Dec 15, 2025 | NetSupport Manager < 14.12.0001 contains an unauthenticated SQL injection vulnerability in its Connectivity Server/Gatew... |
| CVE-2025-14383 | HIGH | 7.5 | 0.4% | Dec 15, 2025 | The Booking Calendar plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'dates_to_check' param... |
| CVE-2025-14156 | CRITICAL | 9.8 | 5.8% | Dec 15, 2025 | The Fox LMS – WordPress LMS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and... |
| CVE-2025-14003 | MEDIUM | 4.3 | 0.2% | Dec 15, 2025 | The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data d... |
| CVE-2025-13950 | MEDIUM | 5.3 | 0.3% | Dec 15, 2025 | The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a ... |
| CVE-2025-13728 | MEDIUM | 6.4 | 0.2% | Dec 15, 2025 | The FluentAuth – The Ultimate Authorization & Security Plugin for WordPress plugin for WordPress is vulnerable to Stored... |
| CVE-2025-13610 | MEDIUM | 6.4 | 0.2% | Dec 15, 2025 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu... |
| CVE-2025-13608 | MEDIUM | 6.4 | 0.2% | Dec 15, 2025 | The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'child_pages' shortcode in ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now