2025 CVE Vulnerabilities
45,181 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14111 | HIGH | 8.1 | 0.5% | Dec 5, 2025 | A security vulnerability has been detected in Rarlab RAR App up to 7.11 Build 127 on Android. This affects an unknown pa... |
| CVE-2025-14108 | HIGH | 8.8 | 9.2% | Dec 5, 2025 | A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this issue is the function zfilev2_api.O... |
| CVE-2025-14107 | HIGH | 8.8 | 10.8% | Dec 5, 2025 | A security flaw has been discovered in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this vulnerability is the function ... |
| CVE-2025-14106 | HIGH | 8.8 | 10.7% | Dec 5, 2025 | A vulnerability was identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected is the function zfilev2_api.CloseSafe of th... |
| CVE-2025-13426 | HIGH | 8.7 | 0.4% | Dec 5, 2025 | A vulnerability exists in Google Apigee's JavaCallout policy https://docs.apigee.com/api-platform/reference/policies/ja... |
| CVE-2025-8148 | MEDIUM | 4.2 | 0.1% | Dec 5, 2025 | An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with a... |
| CVE-2025-14105 | MEDIUM | 4.3 | 0.3% | Dec 5, 2025 | A vulnerability was determined in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. This impacts an unknown function of the ... |
| CVE-2025-66644 | CRITICAL | 9.8 | 3.0% | Dec 5, 2025 | Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2... |
| CVE-2025-66624 | HIGH | 7.5 | 0.4% | Dec 5, 2025 | BACnet Protocol Stack library provides a BACnet application layer, network layer and media access (MAC) layer communicat... |
| CVE-2025-66623 | HIGH | 7.4 | 0.2% | Dec 5, 2025 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. F... |
| CVE-2025-66581 | MEDIUM | 6.5 | 0.2% | Dec 5, 2025 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.41.0, ... |
| CVE-2025-66577 | MEDIUM | 5.3 | 0.2% | Dec 5, 2025 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allow... |
| CVE-2025-66570 | CRITICAL | 9.8 | 0.3% | Dec 5, 2025 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allow... |
| CVE-2025-46603 | HIGH | 7.5 | 0.2% | Dec 5, 2025 | Dell CloudBoost Virtual Appliance, versions 19.13.0.0 and prior, contains an Improper Restriction of Excessive Authentic... |
| CVE-2025-66566 | HIGH | 8.2 | 0.5% | Dec 5, 2025 | yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor... |
| CVE-2025-66562 | CRITICAL | 9.6 | 0.4% | Dec 5, 2025 | TUUI is a desktop MCP client designed as a tool unitary utility integration. Prior to 1.3.4, a critical Remote Code Exec... |
| CVE-2025-66558 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | Nextcloud Twofactor WebAuthn is the WebAuthn Two-Factor Provider for Nextcloud. Prior to 1.4.2 and 2.4.1, a missing owne... |
| CVE-2025-66557 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integra... |
| CVE-2025-66556 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | Nextcloud talk is a video & audio conferencing app for Nextcloud. Prior to 20.1.8 and 21.1.2, a participant with chat pe... |
| CVE-2025-66554 | MEDIUM | 5.4 | 0.2% | Dec 5, 2025 | Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. Prior to 5... |
| CVE-2025-66553 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated u... |
| CVE-2025-66551 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.6 and 0.9.3, a malicious use... |
| CVE-2025-66549 | LOW | 2.7 | 0.2% | Dec 5, 2025 | Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside ... |
| CVE-2025-66548 | MEDIUM | 5.5 | 0.1% | Dec 5, 2025 | Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integra... |
| CVE-2025-66545 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | Nextcloud Groupfolders provides admin-configured folders shared by everyone in a group or team. Prior to 14.0.11, 15.3.1... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now