2025 CVE Vulnerabilities
45,334 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67691 | — | — | — | Dec 11, 2025 | Rejected reason: Not used |
| CVE-2025-67690 | — | — | — | Dec 11, 2025 | Rejected reason: Not used |
| CVE-2025-67689 | — | — | — | Dec 11, 2025 | Rejected reason: Not used |
| CVE-2025-67688 | — | — | — | Dec 11, 2025 | Rejected reason: Not used |
| CVE-2025-67687 | — | — | — | Dec 11, 2025 | Rejected reason: Not used |
| CVE-2025-67686 | — | — | — | Dec 11, 2025 | Rejected reason: Not used |
| CVE-2025-14157 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18... |
| CVE-2025-13978 | MEDIUM | 4.3 | 0.3% | Dec 11, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.4.6, 18.5 before 18.5.4, and 1... |
| CVE-2025-12716 | HIGH | 8.7 | 0.4% | Dec 11, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.4.6, 18.5 before 18.5.4, and 1... |
| CVE-2025-12562 | HIGH | 7.5 | 0.8% | Dec 11, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and ... |
| CVE-2025-10163 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | The List category posts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘starting_with’ parameter... |
| CVE-2025-14485 | MEDIUM | 5 | 1.6% | Dec 11, 2025 | A weakness has been identified in EFM ipTIME A3004T 14.19.0. This vulnerability affects the function show_debug_screen o... |
| CVE-2025-13764 | CRITICAL | 9.8 | 0.3% | Dec 11, 2025 | The WP CarDealer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.16... |
| CVE-2025-11467 | MEDIUM | 5.8 | 0.3% | Dec 11, 2025 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is... |
| CVE-2025-67720 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | Pyrofork is a modern, asynchronous MTProto API framework. Versions 2.3.68 and earlier do not properly sanitize filenames... |
| CVE-2025-67719 | HIGH | 8.5 | 0.1% | Dec 11, 2025 | Ibexa is a composable end-to-end DXP (Digital Experience Platform). Versions 5.0.0-beta1 through 5.0.3 do not have passw... |
| CVE-2025-67718 | HIGH | 8.7 | 0.3% | Dec 11, 2025 | Form.io is a combined Form and API platform for Serverless applications. Versions 3.5.6 and below and 4.0.0-rc.1 through... |
| CVE-2025-67717 | MEDIUM | 4.3 | 0.2% | Dec 11, 2025 | ZITADEL is an open-source identity infrastructure tool. Versions 2.44.0 through 3.4.4 and 4.0.0-rc.1 through 4.7.1 discl... |
| CVE-2025-67716 | MEDIUM | 5.7 | 0.2% | Dec 11, 2025 | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions 4.9.0 through ... |
| CVE-2025-67713 | MEDIUM | 6.1 | 0.2% | Dec 11, 2025 | Miniflux 2 is an open source feed reader. Versions 2.2.14 and below treat redirect_url as safe when url.Parse(...).IsAbs... |
| CVE-2025-67648 | MEDIUM | 6.1 | 0.2% | Dec 11, 2025 | Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XS... |
| CVE-2025-67646 | LOW | 3.5 | 0.1% | Dec 11, 2025 | TableProgressTracking is a MediaWiki extension to track progress against specific criterion. Versions 1.2.0 and below do... |
| CVE-2025-67644 | HIGH | 7.8 | 2.1% | Dec 11, 2025 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, ... |
| CVE-2025-67514 | — | — | — | Dec 11, 2025 | Rejected reason: Vulnerability is dependency-based. |
| CVE-2025-67512 | — | — | — | Dec 11, 2025 | Rejected reason: The vulnerability is dependency-based. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now