2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67780 | MEDIUM | 4.2 | 0.1% | Dec 11, 2025 | SpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on Mini1_prod2) allow administrative actions via un... |
| CVE-2025-66452 | MEDIUM | 6.1 | 0.2% | Dec 11, 2025 | LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, there is no handler for JSON parsing... |
| CVE-2025-66451 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when creating prompts, JSON requests... |
| CVE-2025-66450 | MEDIUM | 5.4 | 0.2% | Dec 11, 2025 | LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when a user posts a question, the ic... |
| CVE-2025-66446 | HIGH | 7.5 | 0.3% | Dec 11, 2025 | MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow... |
| CVE-2025-66419 | CRITICAL | 10 | 0.3% | Dec 11, 2025 | MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to ... |
| CVE-2025-64721 | CRITICAL | 10 | 0.6% | Dec 11, 2025 | Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.... |
| CVE-2025-34506 | HIGH | 8.8 | 0.8% | Dec 11, 2025 | WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrator... |
| CVE-2025-34504 | MEDIUM | 6.1 | 0.3% | Dec 11, 2025 | KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the ... |
| CVE-2025-34499 | MEDIUM | 6.9 | 0.4% | Dec 11, 2025 | AnyDesk 7.0.15 and 9.0.1 contains an unquoted service path vulnerability that allows local non-privileged users to poten... |
| CVE-2025-13668 | MEDIUM | 6.7 | 0.1% | Dec 11, 2025 | A potential security vulnerability in Quartus® Prime Pro Edition Design Software may allow escalation of privilege. |
| CVE-2025-66590 | CRITICAL | 9.8 | 0.3% | Dec 11, 2025 | In AzeoTech DAQFactory release 20.7 (Build 2555), an out-of-bounds write vulnerability can be exploited by an attacker t... |
| CVE-2025-66589 | CRITICAL | 9.1 | 0.4% | Dec 11, 2025 | In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to... |
| CVE-2025-66588 | CRITICAL | 9.8 | 0.2% | Dec 11, 2025 | In AzeoTech DAQFactory release 20.7 (Build 2555), an access of uninitialized pointer vulnerability can be exploited by a... |
| CVE-2025-66587 | — | — | — | Dec 11, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-66586 | HIGH | 7.8 | 0.2% | Dec 11, 2025 | In AzeoTech DAQFactory release 20.7 (Build 2555), an access of resource using incompatible type vulnerability can be exp... |
| CVE-2025-66585 | HIGH | 7.8 | 0.2% | Dec 11, 2025 | In AzeoTech DAQFactory release 20.7 (Build 2555), a use after free vulnerability can be exploited to cause memory corrup... |
| CVE-2025-66584 | — | — | — | Dec 11, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-66429 | HIGH | 8.8 | 0.7% | Dec 11, 2025 | An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allow... |
| CVE-2025-64702 | MEDIUM | 5.3 | 0.3% | Dec 11, 2025 | quic-go is an implementation of the QUIC protocol in Go. Versions 0.56.0 and below are vulnerable to excessive memory al... |
| CVE-2025-55816 | MEDIUM | 6.1 | 0.2% | Dec 11, 2025 | HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file. |
| CVE-2025-14538 | LOW | 3.5 | 0.2% | Dec 11, 2025 | A security vulnerability has been detected in yangshare warehouseManager 仓库管理系统 1.1.0. This affects the function addCust... |
| CVE-2025-14537 | CRITICAL | 9.8 | 0.4% | Dec 11, 2025 | A weakness has been identified in code-projects Class and Exam Timetable Management 1.0. Affected by this issue is some ... |
| CVE-2025-14293 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 ... |
| CVE-2025-13664 | MEDIUM | 6.7 | 0.1% | Dec 11, 2025 | A potential security vulnerability in Quartus® Prime Standard Edition Design Software may allow escalation of privilege. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now