2025 CVE Vulnerabilities
45,179 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22432 | MEDIUM | 6.7 | 0.1% | Dec 8, 2025 | In notifyTimeout of CallRedirectionProcessor.java, there is a possible persistent connection due to improper input valid... |
| CVE-2025-22420 | HIGH | 7.8 | 0.1% | Dec 8, 2025 | In multiple locations, there is a possible way to leak audio files across user profiles due to a confused deputy. This c... |
| CVE-2025-14257 | CRITICAL | 9.8 | 0.4% | Dec 8, 2025 | A flaw has been found in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /newrec... |
| CVE-2025-14256 | CRITICAL | 9.8 | 0.4% | Dec 8, 2025 | A vulnerability was detected in itsourcecode Student Management System 1.0. This impacts an unknown function of the file... |
| CVE-2025-65798 | MEDIUM | 5.4 | 0.2% | Dec 8, 2025 | Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or d... |
| CVE-2025-65796 | MEDIUM | 4.3 | 0.2% | Dec 8, 2025 | Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reac... |
| CVE-2025-61318 | CRITICAL | 9.1 | 0.6% | Dec 8, 2025 | Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php comp... |
| CVE-2025-14271 | — | — | — | Dec 8, 2025 | Rejected reason: This CVE ID has been withdrawn by its CVE Numbering Authority. |
| CVE-2025-14251 | CRITICAL | 9.8 | 0.3% | Dec 8, 2025 | A security vulnerability has been detected in code-projects Online Ordering System 1.0. This affects an unknown function... |
| CVE-2025-14250 | CRITICAL | 9.8 | 0.3% | Dec 8, 2025 | A weakness has been identified in code-projects Online Ordering System 1.0. The impacted element is an unknown function ... |
| CVE-2025-60912 | LOW | 3.3 | 0.2% | Dec 8, 2025 | phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The gene... |
| CVE-2025-14249 | CRITICAL | 9.8 | 0.3% | Dec 8, 2025 | A security flaw has been discovered in code-projects Online Ordering System 1.0. The affected element is an unknown func... |
| CVE-2025-14248 | CRITICAL | 9.8 | 0.3% | Dec 8, 2025 | A vulnerability was identified in code-projects Simple Shopping Cart 1.0. Impacted is an unknown function of the file /a... |
| CVE-2025-14247 | CRITICAL | 9.8 | 0.3% | Dec 8, 2025 | A vulnerability was determined in code-projects Simple Shopping Cart 1.0. This issue affects some unknown processing of ... |
| CVE-2025-14246 | CRITICAL | 9.8 | 0.3% | Dec 8, 2025 | A vulnerability was found in code-projects Simple Shopping Cart 1.0. This vulnerability affects unknown code of the file... |
| CVE-2025-42620 | HIGH | 8.3 | 0.2% | Dec 8, 2025 | In affected versions, vulnerability-lookup handled user-controlled content in comments and bundles in an unsafe way, wh... |
| CVE-2025-42616 | HIGH | 7 | 0.1% | Dec 8, 2025 | Some endpoints in vulnerability-lookup that modified application state (e.g. changing database entries, user data, con... |
| CVE-2025-14245 | CRITICAL | 9.8 | 0.3% | Dec 8, 2025 | A vulnerability has been found in IdeaCMS up to 1.8. This affects the function whereRaw of the file app/common/logic/ind... |
| CVE-2025-42615 | HIGH | 8.1 | 0.3% | Dec 8, 2025 | In affected versions, vulnerability-lookup did not track or limit failed One-Time Password (OTP) attempts during Two-Fa... |
| CVE-2025-14244 | MEDIUM | 4.8 | 0.2% | Dec 8, 2025 | A flaw has been found in GreenCMS 2.3.0603. Affected by this issue is some unknown functionality of the file /Admin/Cont... |
| CVE-2025-14230 | HIGH | 8.8 | 0.3% | Dec 8, 2025 | A vulnerability was detected in code-projects Daily Time Recording System 4.5.0. The impacted element is an unknown func... |
| CVE-2025-14229 | HIGH | 8 | 0.3% | Dec 8, 2025 | A security vulnerability has been detected in SourceCodester Inventory Management System 1.0. The affected element is an... |
| CVE-2025-14228 | LOW | 3.5 | 0.2% | Dec 8, 2025 | A weakness has been identified in Yealink SIP-T21P E2 52.84.0.15. Impacted is an unknown function of the component Local... |
| CVE-2025-66461 | HIGH | 8.4 | 0.1% | Dec 8, 2025 | FULLBACK Manager Pro provided by GS Yuasa International Ltd. registers two Windows services with unquoted file paths. A... |
| CVE-2025-27020 | CRITICAL | 9.8 | 0.5% | Dec 8, 2025 | Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary comm... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now