2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34499 | MEDIUM | 6.9 | 0.4% | Dec 11, 2025 | AnyDesk 7.0.15 and 9.0.1 contains an unquoted service path vulnerability that allows local non-privileged users to poten... |
| CVE-2025-13668 | MEDIUM | 6.7 | 0.1% | Dec 11, 2025 | A potential security vulnerability in Quartus® Prime Pro Edition Design Software may allow escalation of privilege. |
| CVE-2025-66590 | CRITICAL | 9.8 | 0.3% | Dec 11, 2025 | In AzeoTech DAQFactory release 20.7 (Build 2555), an out-of-bounds write vulnerability can be exploited by an attacker t... |
| CVE-2025-66589 | CRITICAL | 9.1 | 0.3% | Dec 11, 2025 | In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to... |
| CVE-2025-66588 | CRITICAL | 9.8 | 0.2% | Dec 11, 2025 | In AzeoTech DAQFactory release 20.7 (Build 2555), an access of uninitialized pointer vulnerability can be exploited by a... |
| CVE-2025-66587 | — | — | — | Dec 11, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-66586 | HIGH | 7.8 | 0.2% | Dec 11, 2025 | In AzeoTech DAQFactory release 20.7 (Build 2555), an access of resource using incompatible type vulnerability can be exp... |
| CVE-2025-66585 | HIGH | 7.8 | 0.2% | Dec 11, 2025 | In AzeoTech DAQFactory release 20.7 (Build 2555), a use after free vulnerability can be exploited to cause memory corrup... |
| CVE-2025-66584 | — | — | — | Dec 11, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-66429 | HIGH | 8.8 | 0.7% | Dec 11, 2025 | An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allow... |
| CVE-2025-64702 | MEDIUM | 5.3 | 0.3% | Dec 11, 2025 | quic-go is an implementation of the QUIC protocol in Go. Versions 0.56.0 and below are vulnerable to excessive memory al... |
| CVE-2025-55816 | MEDIUM | 6.1 | 0.2% | Dec 11, 2025 | HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file. |
| CVE-2025-14538 | LOW | 3.5 | 0.2% | Dec 11, 2025 | A security vulnerability has been detected in yangshare warehouseManager 仓库管理系统 1.1.0. This affects the function addCust... |
| CVE-2025-14537 | CRITICAL | 9.8 | 0.4% | Dec 11, 2025 | A weakness has been identified in code-projects Class and Exam Timetable Management 1.0. Affected by this issue is some ... |
| CVE-2025-14293 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 ... |
| CVE-2025-13664 | MEDIUM | 6.7 | 0.1% | Dec 11, 2025 | A potential security vulnerability in Quartus® Prime Standard Edition Design Software may allow escalation of privilege. |
| CVE-2025-13663 | MEDIUM | 6.7 | 0.1% | Dec 11, 2025 | Under certain circumstances, the Quartus Prime Pro Installer for Windows does not check the permissions of the Quartus t... |
| CVE-2025-55184 | HIGH | 7.5 | 65.6% | Dec 11, 2025 | A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 1... |
| CVE-2025-55183 | MEDIUM | 5.3 | 62.4% | Dec 11, 2025 | An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 1... |
| CVE-2025-36938 | MEDIUM | 6.8 | 0.1% | Dec 11, 2025 | In U-Boot of append_uint32_le(), there is a possible fault injection due to a logic error in the code. This could lead t... |
| CVE-2025-36937 | CRITICAL | 9.8 | 0.2% | Dec 11, 2025 | In AudioDecoder::HandleProduceRequest of audio_decoder.cc, there is a possible out of bounds write due to an incorrect b... |
| CVE-2025-36936 | HIGH | 7.8 | 0.1% | Dec 11, 2025 | In GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to an integer overflow. Thi... |
| CVE-2025-36935 | HIGH | 7.8 | 0.1% | Dec 11, 2025 | In trusty_ffa_mem_reclaim of shared-mem-smcall.c, there is a possible memory corruption due to uninitialized data. This ... |
| CVE-2025-36934 | HIGH | 7.4 | 0.1% | Dec 11, 2025 | In bigo_worker_thread of private/google-modules/video/gchips/bigo.c, there is a possible use after free due to a race co... |
| CVE-2025-36932 | HIGH | 7.8 | 0.1% | Dec 11, 2025 | In tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory overwrite due to imp... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now