2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-56157 | CRITICAL | 9.8 | 0.8% | Dec 18, 2025 | Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file inclu... |
| CVE-2025-64236 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Tuturn allows Authentication Abuse.... |
| CVE-2025-14879 | CRITICAL | 9.8 | 5.9% | Dec 18, 2025 | A weakness has been identified in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/onSSIDChange... |
| CVE-2025-63389 | CRITICAL | 9.8 | 0.6% | Dec 18, 2025 | A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and includ... |
| CVE-2025-63388 | CRITICAL | 9.1 | 0.2% | Dec 18, 2025 | A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-f... |
| CVE-2025-63386 | CRITICAL | 9.1 | 0.2% | Dec 18, 2025 | A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup en... |
| CVE-2025-14878 | CRITICAL | 9.8 | 0.8% | Dec 18, 2025 | A security flaw has been discovered in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/wirele... |
| CVE-2025-14877 | CRITICAL | 9.8 | 0.3% | Dec 18, 2025 | A vulnerability was identified in Campcodes Supplier Management System 1.0. This affects an unknown function of the file... |
| CVE-2025-7358 | CRITICAL | 9.8 | 0.3% | Dec 18, 2025 | Use of Hard-coded Credentials vulnerability in Utarit Informatics Services Inc. SoliClub allows Authentication Abuse. T... |
| CVE-2025-65008 | CRITICAL | 9.4 | 2.4% | Dec 18, 2025 | In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of validation in the langGet parameter in ... |
| CVE-2025-14860 | CRITICAL | 9.8 | 0.3% | Dec 18, 2025 | Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146.0.1. |
| CVE-2025-10910 | CRITICAL | 9.3 | 0.4% | Dec 18, 2025 | A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online... |
| CVE-2025-66078 | CRITICAL | 9.1 | 0.3% | Dec 18, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters Hotel Booking Lite motopress-hote... |
| CVE-2025-66074 | CRITICAL | 9 | 0.2% | Dec 18, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Path Traversa... |
| CVE-2025-64374 | CRITICAL | 9.9 | 0.3% | Dec 18, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in StylemixThemes Motors motors allows Using Malicious Fil... |
| CVE-2025-64233 | CRITICAL | 9.8 | 0.3% | Dec 18, 2025 | Deserialization of Untrusted Data vulnerability in BoldThemes Codiqa codiqa allows Object Injection.This issue affects C... |
| CVE-2025-64231 | CRITICAL | 9.9 | 0.3% | Dec 18, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google S... |
| CVE-2025-64227 | CRITICAL | 9.8 | 0.3% | Dec 18, 2025 | Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows O... |
| CVE-2025-64206 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Deserialization of Untrusted Data vulnerability in TieLabs Jannah jannah allows Object Injection.This issue affects Jann... |
| CVE-2025-64188 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affec... |
| CVE-2025-60180 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce-crmperks allows O... |
| CVE-2025-60178 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allows Object Injection... |
| CVE-2025-60174 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin gf-constant-contac... |
| CVE-2025-60091 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Object I... |
| CVE-2025-60090 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Insightly gf-insightly allows Object Injec... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now