2025 CVE Vulnerabilities
45,181 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66506 | HIGH | 7.5 | 0.2% | Dec 4, 2025 | Fulcio is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identit... |
| CVE-2025-66238 | HIGH | 7.4 | 0.3% | Dec 4, 2025 | DCIM dcTrack allows an attacker to misuse certain remote access features. An authenticated user with access to the appli... |
| CVE-2025-65900 | MEDIUM | 6.5 | 0.3% | Dec 4, 2025 | Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due... |
| CVE-2025-65899 | MEDIUM | 5.3 | 0.3% | Dec 4, 2025 | Kalmia CMS version 0.2.0 contains a user enumeration vulnerability in its authentication mechanism. The application retu... |
| CVE-2025-53704 | HIGH | 8.7 | 0.2% | Dec 4, 2025 | The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the acc... |
| CVE-2025-1910 | MEDIUM | 6.3 | 0.2% | Dec 4, 2025 | The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to e... |
| CVE-2025-1547 | HIGH | 7.2 | 0.3% | Dec 4, 2025 | A stack-based buffer overflow vulnerability [CWE-121] in WatchGuard Fireware OS's certificate request command could allo... |
| CVE-2025-1545 | HIGH | 7.5 | 0.5% | Dec 4, 2025 | An XPath Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensi... |
| CVE-2025-13940 | MEDIUM | 5.5 | 0.1% | Dec 4, 2025 | An Expected Behavior Violation [CWE-440] vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fir... |
| CVE-2025-13939 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ... |
| CVE-2025-13938 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ... |
| CVE-2025-13937 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ... |
| CVE-2025-13936 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ... |
| CVE-2025-13932 | HIGH | 8.3 | 0.2% | Dec 4, 2025 | The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Reference ... |
| CVE-2025-12986 | MEDIUM | 6 | 0.2% | Dec 4, 2025 | When a WF200/WGM160P device is configured to operate as an Access Point, it may be vulnerable to a denial of service tri... |
| CVE-2025-12196 | HIGH | 7.2 | 0.6% | Dec 4, 2025 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to exe... |
| CVE-2025-12195 | HIGH | 7.2 | 0.6% | Dec 4, 2025 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to exe... |
| CVE-2025-12026 | HIGH | 7.2 | 0.4% | Dec 4, 2025 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could allow an authenticate... |
| CVE-2025-11838 | HIGH | 7.5 | 0.5% | Dec 4, 2025 | A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of... |
| CVE-2025-10285 | HIGH | 7.4 | 0.2% | Dec 4, 2025 | The web interface of the Silicon Labs Simplicity Device Manager is exposed publicly and can be used to extract the NTLMv... |
| CVE-2025-66576 | CRITICAL | 9.8 | 1.1% | Dec 4, 2025 | Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function... |
| CVE-2025-66575 | HIGH | 7.8 | 0.4% | Dec 4, 2025 | VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute... |
| CVE-2025-66574 | MEDIUM | 5.4 | 0.2% | Dec 4, 2025 | TranzAxis 3.2.41.10.26 allows authenticated users to inject cross-site scripting via the `Open Object in Tree` endpoint,... |
| CVE-2025-66573 | HIGH | 7.5 | 0.3% | Dec 4, 2025 | Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive info... |
| CVE-2025-66572 | MEDIUM | 6.9 | 0.4% | Dec 4, 2025 | Loaded Commerce 6.6 contains a client-side template injection vulnerability via the search parameter that allows unauthe... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now