2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68270 | CRITICAL | 9.9 | 0.3% | Dec 16, 2025 | The Open edX Platform is a learning management platform. Prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, Cours... |
| CVE-2025-62864 | CRITICAL | 9.8 | 0.3% | Dec 16, 2025 | Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.... |
| CVE-2025-62863 | CRITICAL | 9.8 | 0.3% | Dec 16, 2025 | Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.... |
| CVE-2025-46295 | CRITICAL | 9.8 | 0.9% | Dec 16, 2025 | Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications pass... |
| CVE-2025-33210 | CRITICAL | 9 | 0.5% | Dec 16, 2025 | NVIDIA Isaac Lab contains a deserialization vulnerability. A successful exploit of this vulnerability might lead to cod... |
| CVE-2025-63414 | CRITICAL | 10 | 1.6% | Dec 16, 2025 | A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to a... |
| CVE-2025-50401 | CRITICAL | 9.8 | 0.4% | Dec 16, 2025 | Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the pa... |
| CVE-2025-50398 | CRITICAL | 9.8 | 0.4% | Dec 16, 2025 | Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the pa... |
| CVE-2025-37164 | CRITICAL | 9.8 | 89.7% | Dec 16, 2025 | A remote code execution issue exists in HPE OneView. |
| CVE-2025-68315 | CRITICAL | 9.8 | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to detect potential corrupted nid in free... |
| CVE-2025-68301 | CRITICAL | 9.8 | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: atlantic: fix fragment overflow handling in RX... |
| CVE-2025-68285 | CRITICAL | 9.8 | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: libceph: fix potential use-after-free in have_mon_a... |
| CVE-2025-68284 | CRITICAL | 9.8 | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds writes in ... |
| CVE-2025-65319 | CRITICAL | 9.1 | 0.5% | Dec 16, 2025 | When using the attachment interaction functionality, Blue Mail 1.140.103 and below saves documents to a file system with... |
| CVE-2025-65318 | CRITICAL | 9.1 | 0.5% | Dec 16, 2025 | When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system witho... |
| CVE-2025-68263 | CRITICAL | 9.8 | 0.4% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: ipc: fix use-after-free in ipc_msg_send_requ... |
| CVE-2025-68192 | CRITICAL | 9.8 | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: usb: qmi_wwan: initialize MAC header offset in... |
| CVE-2025-40350 | CRITICAL | 9.8 | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix generating skb from non-linear x... |
| CVE-2025-62849 | CRITICAL | 9.8 | 0.9% | Dec 16, 2025 | An SQL injection vulnerability has been reported to affect several QNAP operating system versions. The remote attackers ... |
| CVE-2025-59385 | CRITICAL | 9.8 | 0.6% | Dec 16, 2025 | An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. T... |
| CVE-2025-67744 | CRITICAL | 9.6 | 0.5% | Dec 16, 2025 | DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to versi... |
| CVE-2025-64725 | CRITICAL | 9.8 | 0.3% | Dec 15, 2025 | Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a... |
| CVE-2025-59947 | CRITICAL | 9 | 0.3% | Dec 15, 2025 | NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBL... |
| CVE-2025-55895 | CRITICAL | 9.1 | 0.3% | Dec 15, 2025 | TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to I... |
| CVE-2025-65213 | CRITICAL | 9.8 | 0.6% | Dec 15, 2025 | MooreThreads torch_musa through all versions contains an unsafe deserialization vulnerability in torch_musa.utils.compar... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now