2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65572 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | Cross Site Scripting (XSS) vulnerability in AllskyTeam AllSky v2024.12.06_06 allows remote attackers to execute arbitrar... |
| CVE-2025-65300 | MEDIUM | 5.4 | 0.2% | Dec 9, 2025 | A stored Cross-Site Scripting (XSS) vulnerability exists in the Coohom SaaS Platform feVersion=1760060603897 (2025-10-28... |
| CVE-2025-14336 | CRITICAL | 9.8 | 0.3% | Dec 9, 2025 | A vulnerability was found in itsourcecode Student Management System 1.0. Affected by this issue is some unknown function... |
| CVE-2025-14335 | CRITICAL | 9.8 | 0.3% | Dec 9, 2025 | A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unkno... |
| CVE-2025-14334 | CRITICAL | 9.8 | 0.3% | Dec 9, 2025 | A flaw has been found in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /new_ad... |
| CVE-2025-11531 | HIGH | 8.8 | 0.3% | Dec 9, 2025 | HP System Event Utility and Omen Gaming Hub might allow execution of certain files outside of their restricted paths. T... |
| CVE-2025-65594 | HIGH | 8.1 | 0.3% | Dec 9, 2025 | OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privil... |
| CVE-2025-64894 | MEDIUM | 5.5 | 0.1% | Dec 9, 2025 | DNG SDK versions 1.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead to ap... |
| CVE-2025-64893 | HIGH | 7.1 | 0.1% | Dec 9, 2025 | DNG SDK versions 1.7.0 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposur... |
| CVE-2025-64784 | HIGH | 7.1 | 0.2% | Dec 9, 2025 | DNG SDK versions 1.7.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory ... |
| CVE-2025-64783 | HIGH | 7.8 | 0.2% | Dec 9, 2025 | DNG SDK versions 1.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in ... |
| CVE-2025-64680 | HIGH | 7.8 | 0.4% | Dec 9, 2025 | Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
| CVE-2025-64679 | HIGH | 7.8 | 0.4% | Dec 9, 2025 | Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
| CVE-2025-64678 | HIGH | 8.8 | 1.0% | Dec 9, 2025 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut... |
| CVE-2025-64673 | HIGH | 7.8 | 0.3% | Dec 9, 2025 | Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally. |
| CVE-2025-64672 | CRITICAL | 9 | 1.0% | Dec 9, 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2025-64671 | HIGH | 7.8 | 0.3% | Dec 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at... |
| CVE-2025-64670 | MEDIUM | 6.5 | 0.9% | Dec 9, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker... |
| CVE-2025-64667 | MEDIUM | 5.3 | 0.8% | Dec 9, 2025 | User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attack... |
| CVE-2025-64666 | HIGH | 7.5 | 1.0% | Dec 9, 2025 | Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a networ... |
| CVE-2025-64661 | HIGH | 7.8 | 0.2% | Dec 9, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an a... |
| CVE-2025-64658 | HIGH | 7.5 | 0.3% | Dec 9, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an a... |
| CVE-2025-64471 | HIGH | 7.5 | 0.3% | Dec 9, 2025 | A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb... |
| CVE-2025-64447 | HIGH | 8.1 | 7.4% | Dec 9, 2025 | A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, ... |
| CVE-2025-64156 | HIGH | 7.2 | 0.3% | Dec 9, 2025 | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiV... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now