2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58053 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | Galette is a membership management web application for non profit organizations. Prior to version 1.2.0, while updating ... |
| CVE-2025-34433 | CRITICAL | 9.3 | 1.5% | Dec 19, 2025 | AVideo versions 14.3.1 prior to 20.1 contain an unauthenticated remote code execution vulnerability caused by predictabl... |
| CVE-2025-14952 | CRITICAL | 9.8 | 0.4% | Dec 19, 2025 | A vulnerability was detected in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /... |
| CVE-2025-14951 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | A security vulnerability has been detected in code-projects Scholars Tracking System 1.0. The impacted element is an unk... |
| CVE-2025-14950 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | A weakness has been identified in code-projects Scholars Tracking System 1.0. The affected element is an unknown functio... |
| CVE-2025-1928 | CRITICAL | 9.1 | 0.3% | Dec 19, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Restajet Information Technologies Inc. Online... |
| CVE-2025-14940 | CRITICAL | 9.8 | 0.3% | Dec 19, 2025 | A vulnerability was determined in code-projects Scholars Tracking System 1.0. The affected element is an unknown functio... |
| CVE-2025-67843 | CRITICAL | 9.8 | 1.1% | Dec 19, 2025 | A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15... |
| CVE-2025-14733 | CRITICAL | 9.8 | 26.5% | Dec 19, 2025 | An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attac... |
| CVE-2025-64675 | CRITICAL | 9.6 | 0.6% | Dec 19, 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauth... |
| CVE-2025-68398 | CRITICAL | 9.1 | 0.5% | Dec 18, 2025 | Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration re... |
| CVE-2025-65041 | CRITICAL | 9.8 | 0.7% | Dec 18, 2025 | Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2025-65037 | CRITICAL | 10 | 0.9% | Dec 18, 2025 | Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to exe... |
| CVE-2025-34449 | CRITICAL | 9.1 | 0.3% | Dec 18, 2025 | Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability i... |
| CVE-2025-14850 | CRITICAL | 9.1 | 0.8% | Dec 18, 2025 | Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files. |
| CVE-2025-14849 | CRITICAL | 9.8 | 0.5% | Dec 18, 2025 | Advantech WebAccess/SCADA is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute ar... |
| CVE-2025-56157 | CRITICAL | 9.8 | 0.8% | Dec 18, 2025 | Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file inclu... |
| CVE-2025-64236 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Tuturn allows Authentication Abuse.... |
| CVE-2025-14879 | CRITICAL | 9.8 | 5.9% | Dec 18, 2025 | A weakness has been identified in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/onSSIDChange... |
| CVE-2025-63389 | CRITICAL | 9.8 | 0.6% | Dec 18, 2025 | A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and includ... |
| CVE-2025-63388 | CRITICAL | 9.1 | 0.2% | Dec 18, 2025 | A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-f... |
| CVE-2025-63386 | CRITICAL | 9.1 | 0.2% | Dec 18, 2025 | A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup en... |
| CVE-2025-14878 | CRITICAL | 9.8 | 0.8% | Dec 18, 2025 | A security flaw has been discovered in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/wirele... |
| CVE-2025-14877 | CRITICAL | 9.8 | 0.3% | Dec 18, 2025 | A vulnerability was identified in Campcodes Supplier Management System 1.0. This affects an unknown function of the file... |
| CVE-2025-7358 | CRITICAL | 9.8 | 0.3% | Dec 18, 2025 | Use of Hard-coded Credentials vulnerability in Utarit Informatics Services Inc. SoliClub allows Authentication Abuse. T... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now