2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66469 | MEDIUM | 6.1 | 0.2% | Dec 9, 2025 | NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to Reflected XSS through its ui.add_css,... |
| CVE-2025-66204 | HIGH | 8.1 | 0.4% | Dec 9, 2025 | WBCE CMS is a content management system. Version 1.6.4 contains a brute-force protection bypass where an attacker can in... |
| CVE-2025-66202 | MEDIUM | 6.5 | 0.3% | Dec 9, 2025 | Astro is a web framework. Versions 5.15.7 and below have a double URL encoding bypass which allows any unauthenticated a... |
| CVE-2025-65964 | HIGH | 8.8 | 0.6% | Dec 9, 2025 | n8n is an open source workflow automation platform. Versions 0.123.1 through 1.119.1 do not have adequate protections to... |
| CVE-2025-65962 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Comm... |
| CVE-2025-64760 | MEDIUM | 4.3 | 0.1% | Dec 8, 2025 | Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Comm... |
| CVE-2025-64499 | MEDIUM | 5.4 | 0.1% | Dec 8, 2025 | Tuleap is a free and open source suite for management of software development and collaboration. Tuleap Community Editon... |
| CVE-2025-64498 | MEDIUM | 4.3 | 0.1% | Dec 8, 2025 | Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap Community Edition versio... |
| CVE-2025-64497 | MEDIUM | 6.5 | 0.2% | Dec 8, 2025 | Tuleap is an Open Source Suite for management of software development and collaboration. Versions below 17.0.99.17624313... |
| CVE-2025-36140 | MEDIUM | 6.5 | 0.2% | Dec 8, 2025 | IBM watsonx.data 2.2 through 2.2.1 could allow an authenticated user to cause a denial of service through ingestion pods... |
| CVE-2025-64650 | MEDIUM | 6.5 | 0.2% | Dec 8, 2025 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.18 could disclose sensitive user credentials in log files. |
| CVE-2025-62408 | MEDIUM | 5.9 | 0.4% | Dec 8, 2025 | c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts whe... |
| CVE-2025-36102 | LOW | 2.7 | 0.2% | Dec 8, 2025 | IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow a privileged user t... |
| CVE-2025-36017 | MEDIUM | 6.5 | 0.2% | Dec 8, 2025 | IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive in... |
| CVE-2025-36015 | MEDIUM | 6.5 | 0.2% | Dec 8, 2025 | IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow an authenticated us... |
| CVE-2025-33111 | MEDIUM | 4.3 | 0.2% | Dec 8, 2025 | IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 is vulnerable to creation of te... |
| CVE-2025-14276 | MEDIUM | 5.6 | 1.5% | Dec 8, 2025 | A vulnerability was determined in Ilevia EVE X1 Server up to 4.6.5.0.eden. Impacted is an unknown function of the file /... |
| CVE-2025-12832 | MEDIUM | 4.3 | 0.2% | Dec 8, 2025 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This ma... |
| CVE-2025-12635 | MEDIUM | 5.4 | 0.1% | Dec 8, 2025 | IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are af... |
| CVE-2025-65228 | LOW | 3.5 | 0.2% | Dec 8, 2025 | A stored cross-site scripting vulnerability exists in the web management interface of the R.V.R. Elettronica TLK302T tel... |
| CVE-2025-65230 | MEDIUM | 5.4 | 0.2% | Dec 8, 2025 | Barix Instreamer v04.06 and v04.05 contains a stored cross-site scripting (XSS) vulnerability in the Web UI Configuratio... |
| CVE-2025-65229 | MEDIUM | 4.6 | 0.1% | Dec 8, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the web interface of Lyrion Music Server <= 9.0.3. An authen... |
| CVE-2025-65849 | CRITICAL | 9.1 | 0.2% | Dec 8, 2025 | A cryptanalytic break in Altcha Proof-of-Work obfuscation mode version 0.8.0 and later allows for remote visitors to rec... |
| CVE-2025-65548 | CRITICAL | 9.1 | 0.4% | Dec 8, 2025 | NUT-14 allows cashu tokens to be created with a preimage hash. However, nutshell (cashubtc/nuts) before 0.18.0 do not va... |
| CVE-2025-65271 | HIGH | 8.8 | 0.4% | Dec 8, 2025 | Client-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary te... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now