2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60089 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Objec... |
| CVE-2025-60062 | CRITICAL | 9.3 | 0.3% | Dec 18, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mmetrodw tPlayer t... |
| CVE-2025-58951 | CRITICAL | 9.3 | 0.3% | Dec 18, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Advance S... |
| CVE-2025-58935 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-54723 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Deserialization of Untrusted Data vulnerability in BoldThemes DentiCare denticare allows Object Injection.This issue aff... |
| CVE-2025-53433 | CRITICAL | 9.8 | 0.4% | Dec 18, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68435 | CRITICAL | 9.1 | 0.4% | Dec 17, 2025 | Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulne... |
| CVE-2025-68145 | CRITICAL | 9.1 | 6.2% | Dec 17, 2025 | In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operat... |
| CVE-2025-14833 | CRITICAL | 9.8 | 0.3% | Dec 17, 2025 | A security flaw has been discovered in code-projects Online Appointment Booking System 1.0. The impacted element is an u... |
| CVE-2025-68118 | CRITICAL | 9.1 | 0.2% | Dec 17, 2025 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.20.0, a vulnerability exists in Free... |
| CVE-2025-68114 | CRITICAL | 9.8 | 0.2% | Dec 17, 2025 | Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat... |
| CVE-2025-67791 | CRITICAL | 9.8 | 0.3% | Dec 17, 2025 | An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete co... |
| CVE-2025-14832 | CRITICAL | 9.8 | 0.3% | Dec 17, 2025 | A vulnerability was identified in itsourcecode Online Cake Ordering System 1.0. The affected element is an unknown funct... |
| CVE-2025-67793 | CRITICAL | 9.8 | 0.3% | Dec 17, 2025 | An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "M... |
| CVE-2025-67493 | CRITICAL | 9 | 0.3% | Dec 17, 2025 | Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed privilege e... |
| CVE-2025-66647 | CRITICAL | 9.8 | 0.8% | Dec 17, 2025 | RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ... |
| CVE-2025-43526 | CRITICAL | 9.8 | 0.5% | Dec 17, 2025 | This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. On a Mac wi... |
| CVE-2025-43428 | CRITICAL | 9.8 | 0.7% | Dec 17, 2025 | A configuration issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS... |
| CVE-2025-67787 | CRITICAL | 9.6 | 0.2% | Dec 17, 2025 | An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allow... |
| CVE-2025-67781 | CRITICAL | 9.9 | 0.2% | Dec 17, 2025 | An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged ... |
| CVE-2025-67073 | CRITICAL | 9.8 | 0.6% | Dec 17, 2025 | A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remot... |
| CVE-2025-34434 | CRITICAL | 9.1 | 0.4% | Dec 17, 2025 | AVideo versions prior to 20.1 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and dele... |
| CVE-2025-62521 | CRITICAL | 9.8 | 4.2% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code executio... |
| CVE-2025-67165 | CRITICAL | 9.8 | 0.4% | Dec 17, 2025 | An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges. |
| CVE-2025-67164 | CRITICAL | 9.9 | 0.4% | Dec 17, 2025 | An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows att... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now