2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34421 | HIGH | 7.8 | 0.2% | Dec 10, 2025 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe... |
| CVE-2025-34420 | HIGH | 7.8 | 0.1% | Dec 10, 2025 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe... |
| CVE-2025-34419 | HIGH | 7.8 | 0.1% | Dec 10, 2025 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe... |
| CVE-2025-34418 | HIGH | 7.8 | 0.1% | Dec 10, 2025 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe... |
| CVE-2025-34417 | HIGH | 7.8 | 0.1% | Dec 10, 2025 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe... |
| CVE-2025-34416 | HIGH | 7.8 | 0.1% | Dec 10, 2025 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe... |
| CVE-2025-34410 | HIGH | 7.1 | 0.1% | Dec 10, 2025 | 1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the Change Username functi... |
| CVE-2025-34395 | HIGH | 7.5 | 0.6% | Dec 10, 2025 | Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting ser... |
| CVE-2025-34394 | CRITICAL | 9.8 | 0.6% | Dec 10, 2025 | Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting ser... |
| CVE-2025-34393 | CRITICAL | 9.8 | 0.6% | Dec 10, 2025 | Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify t... |
| CVE-2025-34392 | CRITICAL | 9.8 | 22.0% | Dec 10, 2025 | Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL def... |
| CVE-2025-13155 | HIGH | 8.5 | 0.1% | Dec 10, 2025 | An improper permissions vulnerability was reported in Lenovo Baiying Client that could allow a local authenticated user ... |
| CVE-2025-13152 | HIGH | 8.5 | 0.1% | Dec 10, 2025 | A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that co... |
| CVE-2025-13125 | MEDIUM | 4.3 | 0.2% | Dec 10, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Im Park Information Technology, Electronics, Press, Pu... |
| CVE-2025-12046 | HIGH | 8.5 | 0.1% | Dec 10, 2025 | A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a lo... |
| CVE-2025-8110 | HIGH | 8.8 | 76.5% | Dec 10, 2025 | Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code. |
| CVE-2025-13127 | LOW | 3.5 | 0.2% | Dec 10, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TAC Informa... |
| CVE-2025-13184 | CRITICAL | 9.8 | 11.0% | Dec 10, 2025 | Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank passw... |
| CVE-2025-41358 | HIGH | 8.3 | 0.3% | Dec 10, 2025 | Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulne... |
| CVE-2025-13953 | CRITICAL | 9.3 | 0.4% | Dec 10, 2025 | Bypass vulnerability in the authentication method in the GTT Tax Information System application, related to the Active D... |
| CVE-2025-41732 | CRITICAL | 9.8 | 0.4% | Dec 10, 2025 | An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary d... |
| CVE-2025-41730 | CRITICAL | 9.8 | 0.4% | Dec 10, 2025 | An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary ... |
| CVE-2025-7073 | HIGH | 7.8 | 0.1% | Dec 10, 2025 | A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privil... |
| CVE-2025-66675 | HIGH | 8.2 | 0.5% | Dec 10, 2025 | Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. Thi... |
| CVE-2025-14390 | HIGH | 8.8 | 0.4% | Dec 10, 2025 | The Video Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in version <= 5.0.4. This is due to ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now