2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66039 | CRITICAL | 9.8 | 3.0% | Dec 9, 2025 | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to aut... |
| CVE-2025-65513 | HIGH | 7.5 | 0.4% | Dec 9, 2025 | fetch-mcp v1.0.2 and before is vulnerable to Server-Side Request Forgery (SSRF) vulnerability, which allows attackers to... |
| CVE-2025-36437 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | IBM Planning Analytics Local 2.1.0 - 2.1.15 could disclose sensitive information about server architecture that could ai... |
| CVE-2025-34425 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the WindowContext par... |
| CVE-2025-67489 | CRITICAL | 9.8 | 0.7% | Dec 9, 2025 | @vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Versions 0.5.5 and below are vulnerable to ar... |
| CVE-2025-67488 | HIGH | 8.8 | 0.4% | Dec 9, 2025 | SiYuan is self-hosted, open source personal knowledge management software. Versions 0.0.0-20251202123337-6ef83b42c7ce an... |
| CVE-2025-66626 | HIGH | 7.5 | 0.6% | Dec 9, 2025 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Version... |
| CVE-2025-64899 | HIGH | 7.8 | 0.4% | Dec 9, 2025 | Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by... |
| CVE-2025-64896 | MEDIUM | 5.5 | 0.2% | Dec 9, 2025 | Creative Cloud Desktop versions 6.4.0.361 and earlier are affected by a Creation of Temporary File in Directory with Inc... |
| CVE-2025-64787 | LOW | 3.3 | 0.4% | Dec 9, 2025 | Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by... |
| CVE-2025-64786 | LOW | 3.3 | 0.4% | Dec 9, 2025 | Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by... |
| CVE-2025-64785 | HIGH | 7.8 | 0.4% | Dec 9, 2025 | Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by... |
| CVE-2025-13743 | HIGH | 7.5 | 0.2% | Dec 9, 2025 | Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serializatio... |
| CVE-2025-66625 | MEDIUM | 4.9 | 0.3% | Dec 9, 2025 | Umbraco is an ASP.NET CMS. Due to unsafe handling and deletion of temporary files in versions 10.0.0 through 13.12.0, du... |
| CVE-2025-66457 | HIGH | 8.8 | 0.7% | Dec 9, 2025 | Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communi... |
| CVE-2025-66456 | CRITICAL | 9.8 | 0.5% | Dec 9, 2025 | Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communi... |
| CVE-2025-66214 | HIGH | 8.8 | 0.3% | Dec 9, 2025 | Ladybug adds message-based debugging, unit, system, and regression testing to Java applications. Versions prior to 3.0-2... |
| CVE-2025-65741 | CRITICAL | 9.8 | 0.4% | Dec 9, 2025 | Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection. An attacker could compile a .dylib file a... |
| CVE-2025-64113 | CRITICAL | 9.8 | 0.6% | Dec 9, 2025 | Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrati... |
| CVE-2025-14337 | CRITICAL | 9.8 | 0.3% | Dec 9, 2025 | A vulnerability was determined in itsourcecode Student Management System 1.0. This affects an unknown part of the file /... |
| CVE-2025-9614 | MEDIUM | 6.5 | 0.1% | Dec 9, 2025 | An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient ... |
| CVE-2025-9613 | MEDIUM | 6.5 | 0.2% | Dec 9, 2025 | A vulnerability was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insuff... |
| CVE-2025-9612 | MEDIUM | 5.1 | 0.1% | Dec 9, 2025 | An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient ... |
| CVE-2025-65882 | CRITICAL | 9.8 | 0.6% | Dec 9, 2025 | An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrad... |
| CVE-2025-65573 | HIGH | 8.8 | 0.3% | Dec 9, 2025 | Cross Site Request Forgery (CSRF) vulnerability in AllskyTeam AllSky v2024.12.06_06 allows remote attackers to cause a d... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now