2025 CVE Vulnerabilities
45,181 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66515 | LOW | 2.7 | 0.3% | Dec 5, 2025 | The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenti... |
| CVE-2025-66514 | MEDIUM | 5.4 | 0.2% | Dec 5, 2025 | Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Prior to 5.5.3, a stored HTML injecti... |
| CVE-2025-66513 | MEDIUM | 5.3 | 0.2% | Dec 5, 2025 | Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.9, 0.9.6, and 1.0.1, the inf... |
| CVE-2025-34266 | MEDIUM | 5.4 | 0.2% | Dec 5, 2025 | Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /r... |
| CVE-2025-34265 | MEDIUM | 5.4 | 0.2% | Dec 5, 2025 | Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /r... |
| CVE-2025-34264 | MEDIUM | 5.4 | 0.2% | Dec 5, 2025 | Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /r... |
| CVE-2025-34263 | MEDIUM | 5.4 | 0.2% | Dec 5, 2025 | Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /r... |
| CVE-2025-34262 | MEDIUM | 5.4 | 0.2% | Dec 5, 2025 | Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /r... |
| CVE-2025-34261 | MEDIUM | 5.4 | 0.2% | Dec 5, 2025 | Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /r... |
| CVE-2025-34260 | MEDIUM | 5.4 | 0.2% | Dec 5, 2025 | Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /r... |
| CVE-2025-34259 | MEDIUM | 5.4 | 0.2% | Dec 5, 2025 | Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /r... |
| CVE-2025-34258 | MEDIUM | 5.4 | 0.2% | Dec 5, 2025 | Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /r... |
| CVE-2025-34257 | MEDIUM | 5.4 | 0.2% | Dec 5, 2025 | Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /r... |
| CVE-2025-34256 | CRITICAL | 9.8 | 0.6% | Dec 5, 2025 | Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product u... |
| CVE-2025-66552 | MEDIUM | 4.3 | 0.3% | Dec 5, 2025 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 3... |
| CVE-2025-66550 | MEDIUM | 5.7 | 0.3% | Dec 5, 2025 | Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.17 and 5.2.4, when a malicious user creates a calendar ... |
| CVE-2025-66547 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-... |
| CVE-2025-66546 | LOW | 3.3 | 0.1% | Dec 5, 2025 | Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly ... |
| CVE-2025-66512 | MEDIUM | 6.1 | 0.2% | Dec 5, 2025 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and ... |
| CVE-2025-66511 | MEDIUM | 6.5 | 0.2% | Dec 5, 2025 | Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for me... |
| CVE-2025-66510 | MEDIUM | 4.9 | 0.3% | Dec 5, 2025 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud E... |
| CVE-2025-66471 | HIGH | 7.5 | 0.6% | Dec 5, 2025 | urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API... |
| CVE-2025-65879 | HIGH | 8.1 | 0.7% | Dec 5, 2025 | Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability. The /goods/deleteGoods ... |
| CVE-2025-65878 | HIGH | 7.5 | 0.6% | Dec 5, 2025 | The warehouse management system version 1.2 contains an arbitrary file read vulnerability. The endpoint `/file/showImage... |
| CVE-2025-65036 | HIGH | 8.3 | 0.3% | Dec 5, 2025 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to 1.2... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now