2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13367 | MEDIUM | 6.4 | 0.3% | Dec 15, 2025 | The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restrict... |
| CVE-2025-12900 | MEDIUM | 4.3 | 0.2% | Dec 15, 2025 | The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to missing authorizatio... |
| CVE-2025-65782 | MEDIUM | 6.5 | 0.2% | Dec 15, 2025 | An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization ... |
| CVE-2025-65781 | HIGH | 8.2 | 0.3% | Dec 15, 2025 | An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upl... |
| CVE-2025-65780 | HIGH | 8.8 | 0.3% | Dec 15, 2025 | An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated ... |
| CVE-2025-65779 | HIGH | 7.5 | 0.3% | Dec 15, 2025 | An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticate... |
| CVE-2025-65778 | HIGH | 8.1 | 0.3% | Dec 15, 2025 | An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attac... |
| CVE-2025-65431 | MEDIUM | 5.4 | 0.1% | Dec 15, 2025 | An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the ident... |
| CVE-2025-65430 | MEDIUM | 5.4 | 0.1% | Dec 15, 2025 | An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tok... |
| CVE-2025-66388 | MEDIUM | 6.5 | 0.4% | Dec 15, 2025 | A vulnerability in Apache Airflow allowed authenticated UI users to view secret values in rendered templates due to secr... |
| CVE-2025-37732 | MEDIUM | 5.4 | 0.2% | Dec 15, 2025 | Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated us... |
| CVE-2025-37731 | HIGH | 7.4 | 0.2% | Dec 15, 2025 | Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica... |
| CVE-2025-14714 | MEDIUM | 6.5 | 0.1% | Dec 15, 2025 | An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the T... |
| CVE-2025-11670 | MEDIUM | 4.3 | 0.4% | Dec 15, 2025 | Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is e... |
| CVE-2025-14711 | CRITICAL | 9.8 | 0.4% | Dec 15, 2025 | A flaw has been found in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This vulnerability a... |
| CVE-2025-14710 | CRITICAL | 9.8 | 0.4% | Dec 15, 2025 | A vulnerability was detected in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This affects ... |
| CVE-2025-14709 | CRITICAL | 9.8 | 5.2% | Dec 15, 2025 | A security vulnerability has been detected in Shiguangwu sgwbox N3 2.0.25. Affected by this issue is some unknown functi... |
| CVE-2025-14708 | HIGH | 7.5 | 6.5% | Dec 15, 2025 | A weakness has been identified in Shiguangwu sgwbox N3 2.0.25. Affected by this vulnerability is an unknown functionalit... |
| CVE-2025-14023 | MEDIUM | 4.3 | 0.1% | Dec 15, 2025 | LINE client for iOS prior to 15.19 allows UI spoofing due to inconsistencies between the navigation state and the in-app... |
| CVE-2025-14022 | MEDIUM | 6.8 | 0.2% | Dec 15, 2025 | LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an ... |
| CVE-2025-14021 | MEDIUM | 4.3 | 0.2% | Dec 15, 2025 | The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could all... |
| CVE-2025-14020 | MEDIUM | 4.3 | 0.1% | Dec 15, 2025 | LINE client for Android versions prior to 14.20 contains a UI spoofing vulnerability in the in-app browser where the ful... |
| CVE-2025-14019 | MEDIUM | 4.7 | 0.1% | Dec 15, 2025 | LINE client for Android versions from 13.8 to 15.5 is vulnerable to UI spoofing in the in-app browser where a specific l... |
| CVE-2025-14712 | HIGH | 8.7 | 0.3% | Dec 15, 2025 | Student Learning Assessment and Support System developed by JHENG GAO has a Exposure of Sensitive Information vulnerabil... |
| CVE-2025-14707 | CRITICAL | 9.8 | 16.5% | Dec 15, 2025 | A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25. Affected is an unknown function of the file /usr/sbi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now