2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34429 | HIGH | 7.1 | 0.1% | Dec 10, 2025 | 1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the web port configuration... |
| CVE-2025-34428 | HIGH | 7.8 | 0.1% | Dec 10, 2025 | MailEnable versions prior to 10.54 contain a cleartext storage of credentials vulnerability that can lead to local crede... |
| CVE-2025-34427 | HIGH | 7.8 | 0.1% | Dec 10, 2025 | MailEnable versions prior to 10.54 contain a cleartext storage of credentials vulnerability that can lead to local crede... |
| CVE-2025-65754 | MEDIUM | 6.1 | 0.4% | Dec 10, 2025 | Cross Site Scripting vulnerability in Algernon v1.17.4 allows attackers to execute arbitrary code via injecting a crafte... |
| CVE-2025-63094 | HIGH | 7.5 | 0.5% | Dec 10, 2025 | XiangShan Nanhu V2 and XiangShan Kunmighu V3 were discovered to use speculative execution and indirect branch prediction... |
| CVE-2025-5467 | LOW | 3.3 | 0.1% | Dec 10, 2025 | It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files ... |
| CVE-2025-13607 | CRITICAL | 9.4 | 0.8% | Dec 10, 2025 | A malicious actor can access camera configuration information, including account credentials, without authenticating whe... |
| CVE-2025-67643 | MEDIUM | 4.3 | 0.3% | Dec 10, 2025 | Jenkins Redpen - Pipeline Reporter for Jira Plugin 1.054.v7b_9517b_6b_202 and earlier does not correctly perform path va... |
| CVE-2025-67642 | MEDIUM | 4.3 | 0.2% | Dec 10, 2025 | Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credential... |
| CVE-2025-67641 | MEDIUM | 5.4 | 0.3% | Dec 10, 2025 | Jenkins Coverage Plugin 2.3054.ve1ff7b_a_a_123b_ and earlier does not validate the configured coverage results ID when c... |
| CVE-2025-67640 | MEDIUM | 5 | 0.2% | Dec 10, 2025 | Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of... |
| CVE-2025-67639 | LOW | 3.5 | 0.2% | Dec 10, 2025 | A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers... |
| CVE-2025-67638 | MEDIUM | 4.3 | 0.1% | Dec 10, 2025 | Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configu... |
| CVE-2025-67637 | MEDIUM | 4.3 | 0.2% | Dec 10, 2025 | Jenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files... |
| CVE-2025-67636 | MEDIUM | 4.3 | 0.2% | Dec 10, 2025 | A missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permiss... |
| CVE-2025-67635 | HIGH | 7.5 | 0.5% | Dec 10, 2025 | Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connectio... |
| CVE-2025-65815 | MEDIUM | 6.5 | 0.5% | Dec 10, 2025 | A lack of security checks in the file import process of AB TECHNOLOGY Document Reader: PDF, DOC, PPT v65.0 allows attack... |
| CVE-2025-65814 | MEDIUM | 6.5 | 0.5% | Dec 10, 2025 | A lack of security checks in the file import process of RHOPHI Analytics LLP Office App-Edit Word v6.4.1 allows attacker... |
| CVE-2025-65792 | CRITICAL | 9.1 | 0.4% | Dec 10, 2025 | DataGear v5.5.0 is vulnerable to Arbitrary File Deletion. |
| CVE-2025-52493 | MEDIUM | 6.5 | 0.3% | Dec 10, 2025 | PagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Altho... |
| CVE-2025-65807 | HIGH | 8.4 | 0.2% | Dec 10, 2025 | An issue in sd command v1.0.0 and before allows attackers to escalate privileges to root via a crafted command. |
| CVE-2025-65803 | MEDIUM | 6.5 | 0.2% | Dec 10, 2025 | An integer overflow in the psdParser::ReadImageData function of FreeImage v3.18.0 and before allows attackers to cause a... |
| CVE-2025-34424 | HIGH | 7.8 | 0.1% | Dec 10, 2025 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe... |
| CVE-2025-34423 | HIGH | 7.8 | 0.1% | Dec 10, 2025 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe... |
| CVE-2025-34422 | HIGH | 7.8 | 0.1% | Dec 10, 2025 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now