2025 CVE Vulnerabilities
45,179 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12635 | MEDIUM | 5.4 | 0.1% | Dec 8, 2025 | IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are af... |
| CVE-2025-65228 | LOW | 3.5 | 0.2% | Dec 8, 2025 | A stored cross-site scripting vulnerability exists in the web management interface of the R.V.R. Elettronica TLK302T tel... |
| CVE-2025-65230 | MEDIUM | 5.4 | 0.2% | Dec 8, 2025 | Barix Instreamer v04.06 and v04.05 contains a stored cross-site scripting (XSS) vulnerability in the Web UI Configuratio... |
| CVE-2025-65229 | MEDIUM | 4.6 | 0.1% | Dec 8, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the web interface of Lyrion Music Server <= 9.0.3. An authen... |
| CVE-2025-65849 | CRITICAL | 9.1 | 0.2% | Dec 8, 2025 | A cryptanalytic break in Altcha Proof-of-Work obfuscation mode version 0.8.0 and later allows for remote visitors to rec... |
| CVE-2025-65548 | CRITICAL | 9.1 | 0.4% | Dec 8, 2025 | NUT-14 allows cashu tokens to be created with a preimage hash. However, nutshell (cashubtc/nuts) before 0.18.0 do not va... |
| CVE-2025-65271 | HIGH | 8.8 | 0.4% | Dec 8, 2025 | Client-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary te... |
| CVE-2025-65231 | MEDIUM | 6.1 | 0.2% | Dec 8, 2025 | Barix Instreamer v04.06 and earlier is vulnerable to Cross Site Scripting (XSS) in the Web UI I/O & Serial configuration... |
| CVE-2025-14261 | HIGH | 7.1 | 0.3% | Dec 8, 2025 | The Litmus platform uses JWT for authentication and authorization, but the secret being used for signing the JWT is only... |
| CVE-2025-65804 | MEDIUM | 6.5 | 0.5% | Dec 8, 2025 | Tenda AX3 v16.03.12.11 contains a stack overflow in formSetIptv via the iptvType parameter, which can cause memory corru... |
| CVE-2025-64081 | CRITICAL | 9.8 | 0.4% | Dec 8, 2025 | SQL injection vulnerability in /php/api_patient_schedule.php in SourceCodester Patients Waiting Area Queue Management Sy... |
| CVE-2025-48625 | HIGH | 7 | 0.1% | Dec 8, 2025 | In multiple locations of UsbDataAdvancedProtectionHook.java, there is a possible way to access USB data when the screen ... |
| CVE-2025-48608 | MEDIUM | 5.5 | 0.1% | Dec 8, 2025 | In isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a missing permission check... |
| CVE-2025-48606 | HIGH | 7.8 | 0.1% | Dec 8, 2025 | In preparePackage of InstallPackageHelper.java, there is a possible way for an app to appear hidden upon installation wi... |
| CVE-2025-48569 | MEDIUM | 5.5 | 0.1% | Dec 8, 2025 | In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to lo... |
| CVE-2025-14259 | MEDIUM | 6.3 | 0.2% | Dec 8, 2025 | A vulnerability was found in Jihai Jshop MiniProgram Mall System 2.9.0. Affected by this issue is some unknown functiona... |
| CVE-2025-14258 | CRITICAL | 9.8 | 0.3% | Dec 8, 2025 | A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unkno... |
| CVE-2025-65799 | MEDIUM | 4.3 | 0.2% | Dec 8, 2025 | A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to e... |
| CVE-2025-65797 | MEDIUM | 6.5 | 0.3% | Dec 8, 2025 | Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level priv... |
| CVE-2025-65795 | HIGH | 7.5 | 0.3% | Dec 8, 2025 | Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create ... |
| CVE-2025-65363 | HIGH | 7.2 | 5.8% | Dec 8, 2025 | Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute app... |
| CVE-2025-63721 | HIGH | 8.8 | 0.4% | Dec 8, 2025 | HummerRisk thru v1.5.0 is using a vulnerable Snakeyaml component, allowing attackers with normal user privileges to hit ... |
| CVE-2025-59391 | MEDIUM | 6.5 | 0.2% | Dec 8, 2025 | A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patche... |
| CVE-2025-48639 | HIGH | 7.3 | 0.1% | Dec 8, 2025 | In DefaultTransitionHandler.java, there is a possible way to unknowingly grant permissions to an app due to a tapjacking... |
| CVE-2025-48638 | HIGH | 7.8 | 0.1% | Dec 8, 2025 | In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now