2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67506 | CRITICAL | 9.8 | 1.6% | Dec 10, 2025 | PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.... |
| CVE-2025-67485 | MEDIUM | 5.3 | 0.2% | Dec 10, 2025 | mad-proxy is a Python-based HTTP/HTTPS proxy server for detection and blocking of malicious web activity using custom se... |
| CVE-2025-67503 | — | — | — | Dec 10, 2025 | Rejected reason: This CVE is a duplicate of another CVE. |
| CVE-2025-67502 | MEDIUM | 6.1 | 0.2% | Dec 10, 2025 | Taguette is an open source qualitative research tool. In versions 1.5.1 and below, attackers can craft malicious URLs t... |
| CVE-2025-67501 | HIGH | 8.8 | 0.4% | Dec 10, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below... |
| CVE-2025-67500 | LOW | 3.7 | 0.2% | Dec 10, 2025 | Mastodon is a free, open-source social network server based on ActivityPub. Versions 4.2.27 and prior, 4.3.0-beta.1 thro... |
| CVE-2025-67499 | LOW | 3.6 | 0.1% | Dec 10, 2025 | The CNI portmap plugin allows containers to emulate opening a host port, forwarding that traffic to the container. Versi... |
| CVE-2025-64898 | MEDIUM | 5.3 | 0.4% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnera... |
| CVE-2025-64897 | MEDIUM | 5.6 | 0.1% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low... |
| CVE-2025-61823 | MEDIUM | 6.2 | 0.4% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity ... |
| CVE-2025-61822 | MEDIUM | 6.2 | 0.6% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that... |
| CVE-2025-61821 | MEDIUM | 6.8 | 0.5% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity ... |
| CVE-2025-61813 | HIGH | 7.4 | 0.5% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity ... |
| CVE-2025-61812 | HIGH | 8.4 | 3.7% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that... |
| CVE-2025-61811 | CRITICAL | 9.1 | 1.0% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that c... |
| CVE-2025-61810 | HIGH | 8.4 | 8.0% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerabili... |
| CVE-2025-61809 | CRITICAL | 9.1 | 0.6% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that... |
| CVE-2025-61808 | CRITICAL | 9.1 | 8.5% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous T... |
| CVE-2025-67498 | — | — | — | Dec 9, 2025 | Rejected reason: Further research determined the issue is not a vulnerability. |
| CVE-2025-67497 | — | — | — | Dec 9, 2025 | Rejected reason: Further research determined the issue is not a vulnerability. |
| CVE-2025-67496 | MEDIUM | 5.4 | 0.2% | Dec 9, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below... |
| CVE-2025-67495 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | ZITADEL is an open-source identity infrastructure tool. Versions 4.0.0-rc.1 through 4.7.0 are vulnerable to DOM-Based XS... |
| CVE-2025-13760 | — | — | — | Dec 9, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-67494 | HIGH | 8.6 | 0.5% | Dec 9, 2025 | ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, f... |
| CVE-2025-66645 | HIGH | 7.5 | 1.0% | Dec 9, 2025 | NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now