2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68118 | CRITICAL | 9.1 | 0.2% | Dec 17, 2025 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.20.0, a vulnerability exists in Free... |
| CVE-2025-68114 | CRITICAL | 9.8 | 0.2% | Dec 17, 2025 | Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat... |
| CVE-2025-67791 | CRITICAL | 9.8 | 0.4% | Dec 17, 2025 | An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete co... |
| CVE-2025-14832 | CRITICAL | 9.8 | 0.3% | Dec 17, 2025 | A vulnerability was identified in itsourcecode Online Cake Ordering System 1.0. The affected element is an unknown funct... |
| CVE-2025-67793 | CRITICAL | 9.8 | 0.3% | Dec 17, 2025 | An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "M... |
| CVE-2025-67493 | CRITICAL | 9 | 0.3% | Dec 17, 2025 | Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed privilege e... |
| CVE-2025-66647 | CRITICAL | 9.8 | 0.8% | Dec 17, 2025 | RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ... |
| CVE-2025-43526 | CRITICAL | 9.8 | 0.5% | Dec 17, 2025 | This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. On a Mac wi... |
| CVE-2025-43428 | CRITICAL | 9.8 | 0.7% | Dec 17, 2025 | A configuration issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS... |
| CVE-2025-67787 | CRITICAL | 9.6 | 0.3% | Dec 17, 2025 | An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allow... |
| CVE-2025-67781 | CRITICAL | 9.9 | 0.2% | Dec 17, 2025 | An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged ... |
| CVE-2025-67073 | CRITICAL | 9.8 | 0.6% | Dec 17, 2025 | A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remot... |
| CVE-2025-34434 | CRITICAL | 9.1 | 0.4% | Dec 17, 2025 | AVideo versions prior to 20.1 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and dele... |
| CVE-2025-62521 | CRITICAL | 9.8 | 4.2% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code executio... |
| CVE-2025-67165 | CRITICAL | 9.8 | 0.4% | Dec 17, 2025 | An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges. |
| CVE-2025-67164 | CRITICAL | 9.9 | 0.4% | Dec 17, 2025 | An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows att... |
| CVE-2025-20393 | CRITICAL | 10 | 29.1% | Dec 17, 2025 | A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure... |
| CVE-2025-44005 | CRITICAL | 10 | 3.3% | Dec 17, 2025 | An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without ... |
| CVE-2025-67895 | CRITICAL | 9.8 | 0.8% | Dec 17, 2025 | Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you in... |
| CVE-2025-59374 | CRITICAL | 9.8 | 1.2% | Dec 17, 2025 | "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modificat... |
| CVE-2025-14700 | CRITICAL | 9.9 | 6.0% | Dec 17, 2025 | An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authentica... |
| CVE-2025-53619 | CRITICAL | 9.1 | 0.2% | Dec 16, 2025 | An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A ... |
| CVE-2025-53618 | CRITICAL | 9.1 | 0.2% | Dec 16, 2025 | An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A ... |
| CVE-2025-48429 | CRITICAL | 9.1 | 0.3% | Dec 16, 2025 | An out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality of Grassroot DICOM 3.024. A sp... |
| CVE-2025-65834 | CRITICAL | 9.8 | 0.3% | Dec 16, 2025 | Meltytech Shotcut 25.10.31 is vulnerable to Buffer Overflow. A memory access violation occurs when processing MLT projec... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now