2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13329 | CRITICAL | 9.8 | 0.6% | Dec 20, 2025 | The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type ... |
| CVE-2025-14968 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | A security flaw has been discovered in code-projects Simple Stock System 1.0. Affected by this issue is some unknown fun... |
| CVE-2025-14967 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | A vulnerability was identified in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unkno... |
| CVE-2025-14964 | CRITICAL | 9.8 | 0.9% | Dec 19, 2025 | A vulnerability has been found in TOTOLINK T10 4.1.8cu.5083_B20200521. This affects the function sprintf of the file /cg... |
| CVE-2025-14961 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | A vulnerability was detected in code-projects Simple Blood Donor Management System 1.0. The affected element is an unkno... |
| CVE-2025-14960 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | A security vulnerability has been detected in code-projects Simple Blood Donor Management System 1.0. Impacted is an unk... |
| CVE-2025-14959 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | A weakness has been identified in code-projects Simple Stock System 1.0. This issue affects some unknown processing of t... |
| CVE-2025-66580 | CRITICAL | 9.6 | 0.5% | Dec 19, 2025 | Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. A critical Stor... |
| CVE-2025-63665 | CRITICAL | 9.8 | 0.4% | Dec 19, 2025 | An issue in GT Edge AI Community Edition Versions before v2.0.12 allows attackers to execute arbitrary code via injectin... |
| CVE-2025-58053 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | Galette is a membership management web application for non profit organizations. Prior to version 1.2.0, while updating ... |
| CVE-2025-34433 | CRITICAL | 9.3 | 1.5% | Dec 19, 2025 | AVideo versions 14.3.1 prior to 20.1 contain an unauthenticated remote code execution vulnerability caused by predictabl... |
| CVE-2025-14952 | CRITICAL | 9.8 | 0.4% | Dec 19, 2025 | A vulnerability was detected in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /... |
| CVE-2025-14951 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | A security vulnerability has been detected in code-projects Scholars Tracking System 1.0. The impacted element is an unk... |
| CVE-2025-14950 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | A weakness has been identified in code-projects Scholars Tracking System 1.0. The affected element is an unknown functio... |
| CVE-2025-1928 | CRITICAL | 9.1 | 0.3% | Dec 19, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Restajet Information Technologies Inc. Online... |
| CVE-2025-14940 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | A vulnerability was determined in code-projects Scholars Tracking System 1.0. The affected element is an unknown functio... |
| CVE-2025-67843 | CRITICAL | 9.8 | 1.1% | Dec 19, 2025 | A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15... |
| CVE-2025-14733 | CRITICAL | 9.8 | 22.3% | Dec 19, 2025 | An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attac... |
| CVE-2025-64675 | CRITICAL | 9.6 | 0.6% | Dec 19, 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauth... |
| CVE-2025-68398 | CRITICAL | 9.1 | 0.5% | Dec 18, 2025 | Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration re... |
| CVE-2025-65041 | CRITICAL | 9.8 | 0.7% | Dec 18, 2025 | Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2025-65037 | CRITICAL | 10 | 0.9% | Dec 18, 2025 | Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to exe... |
| CVE-2025-34449 | CRITICAL | 9.1 | 0.3% | Dec 18, 2025 | Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability i... |
| CVE-2025-14850 | CRITICAL | 9.1 | 0.8% | Dec 18, 2025 | Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files. |
| CVE-2025-14849 | CRITICAL | 9.8 | 0.5% | Dec 18, 2025 | Advantech WebAccess/SCADA is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute ar... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now