2025 CVE Vulnerabilities
45,181 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66571 | CRITICAL | 9.3 | 0.5% | Dec 4, 2025 | UNA CMS versions 9.0.0-RC1 - 14.0.0-RC4 contain a PHP object injection vulnerability in BxBaseMenuSetAclLevel.php where ... |
| CVE-2025-66555 | HIGH | 8.8 | 0.5% | Dec 4, 2025 | AirKeyboard iOS App 1.0.5 contains a missing authentication vulnerability that allows unauthenticated attackers to type ... |
| CVE-2025-66479 | LOW | 1.8 | 0.1% | Dec 4, 2025 | Anthropic Sandbox Runtime is a lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrar... |
| CVE-2025-66237 | HIGH | 8.4 | 0.1% | Dec 4, 2025 | DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to... |
| CVE-2025-65959 | MEDIUM | 5.4 | 0.2% | Dec 4, 2025 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a St... |
| CVE-2025-63896 | HIGH | 7.6 | 0.3% | Dec 4, 2025 | An issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows ... |
| CVE-2025-55948 | HIGH | 7.3 | 0.2% | Dec 4, 2025 | This vulnerability fundamentally arises from yzcheng90 X-SpringBoot 6.0's implementation of role-based access control (R... |
| CVE-2025-27935 | HIGH | 8.6 | 0.4% | Dec 4, 2025 | The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The serv... |
| CVE-2025-13543 | HIGH | 8.8 | 0.7% | Dec 4, 2025 | The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in th... |
| CVE-2025-65958 | HIGH | 7.1 | 4.0% | Dec 4, 2025 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Se... |
| CVE-2025-65883 | HIGH | 8.4 | 0.3% | Dec 4, 2025 | A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local networ... |
| CVE-2025-65806 | MEDIUM | 4.3 | 0.3% | Dec 4, 2025 | The E-POINT CMS eagle.gsam-1169.1 file upload feature improperly handles nested archive files. An attacker can upload a ... |
| CVE-2025-63499 | MEDIUM | 6.1 | 0.3% | Dec 4, 2025 | Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter. |
| CVE-2025-29269 | CRITICAL | 9.8 | 1.9% | Dec 4, 2025 | ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in t... |
| CVE-2025-29268 | CRITICAL | 9.8 | 8.1% | Dec 4, 2025 | ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library. |
| CVE-2025-12997 | LOW | 3.1 | 0.2% | Dec 4, 2025 | Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with... |
| CVE-2025-12996 | MEDIUM | 4.1 | 0.1% | Dec 4, 2025 | Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext ... |
| CVE-2025-12995 | CRITICAL | 9.8 | 0.3% | Dec 4, 2025 | Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint ... |
| CVE-2025-12994 | MEDIUM | 5.3 | 0.3% | Dec 4, 2025 | Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an ... |
| CVE-2025-12097 | HIGH | 8.7 | 0.5% | Dec 4, 2025 | There is a relative path traversal vulnerability in the NI System Web Server that may result in information disclosure. ... |
| CVE-2025-65945 | HIGH | 7.5 | 0.2% | Dec 4, 2025 | auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth... |
| CVE-2025-65637 | HIGH | 7.5 | 0.6% | Dec 4, 2025 | A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line pa... |
| CVE-2025-63362 | CRITICAL | 9.8 | 0.5% | Dec 4, 2025 | Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.00... |
| CVE-2025-63361 | MEDIUM | 5.7 | 0.3% | Dec 4, 2025 | Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.00... |
| CVE-2025-59788 | MEDIUM | 5.4 | 0.2% | Dec 4, 2025 | Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions bef... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now