2025 CVE Vulnerabilities
45,181 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14016 | HIGH | 8.1 | 0.2% | Dec 4, 2025 | A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the ... |
| CVE-2025-14015 | CRITICAL | 9.8 | 0.7% | Dec 4, 2025 | A weakness has been identified in H3C Magic B0 up to 100R002. This impacts the function EditWlanMacList of the file /gof... |
| CVE-2025-14013 | MEDIUM | 4.8 | 0.2% | Dec 4, 2025 | A vulnerability was identified in JIZHICMS up to 2.5.5. The impacted element is an unknown function of the file /index.p... |
| CVE-2025-13488 | MEDIUM | 5.1 | 0.3% | Dec 4, 2025 | Due to a regression introduced in version 3.83.0, a security header is no longer applied to certain user-uploaded conten... |
| CVE-2025-9127 | MEDIUM | 5.5 | 0.1% | Dec 4, 2025 | A vulnerability exists in PX Enterprise whereby sensitive information may be logged under specific conditions. |
| CVE-2025-63363 | HIGH | 7.5 | 0.3% | Dec 4, 2025 | A lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V... |
| CVE-2025-14012 | HIGH | 7.2 | 0.3% | Dec 4, 2025 | A vulnerability was determined in JIZHICMS up to 2.5.5. The affected element is the function deleteAll/findAll/delete of... |
| CVE-2025-14011 | HIGH | 7.2 | 0.3% | Dec 4, 2025 | A vulnerability was found in JIZHICMS up to 2.5.5. Impacted is the function commentlist of the file /index.php/admins/Co... |
| CVE-2025-66516 | CRITICAL | 9.8 | 79.8% | Dec 4, 2025 | Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules... |
| CVE-2025-66373 | MEDIUM | 4.8 | 0.2% | Dec 4, 2025 | Akamai Ghost on Akamai CDN edge servers before 2025-11-17 has a chunked request body processing error that can result in... |
| CVE-2025-66287 | HIGH | 8.8 | 0.4% | Dec 4, 2025 | A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper me... |
| CVE-2025-63364 | HIGH | 7.5 | 0.2% | Dec 4, 2025 | Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.00... |
| CVE-2025-8074 | MEDIUM | 5.6 | 0.1% | Dec 4, 2025 | Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users... |
| CVE-2025-65516 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | A stored cross-site scripting (XSS) vulnerability was discovered in Seafile Community Edition prior to version 13.0.12. ... |
| CVE-2025-63681 | MEDIUM | 4.3 | 0.3% | Dec 4, 2025 | open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tas... |
| CVE-2025-61148 | MEDIUM | 6.5 | 0.3% | Dec 4, 2025 | An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authentic... |
| CVE-2025-57213 | HIGH | 7.5 | 0.2% | Dec 4, 2025 | Incorrect access control in the component orderService.queryObject of platform v1.0.0 allows attackers to access sensiti... |
| CVE-2025-57212 | HIGH | 7.5 | 0.2% | Dec 4, 2025 | Incorrect access control in the component ApiOrderService.java of platform v1.0.0 allows attackers to access sensitive i... |
| CVE-2025-57210 | HIGH | 7.5 | 0.2% | Dec 4, 2025 | Incorrect access control in the component ApiPayController.java of platform v1.0.0 allows attackers to access sensitive ... |
| CVE-2025-56427 | HIGH | 7.5 | 0.8% | Dec 4, 2025 | Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via th... |
| CVE-2025-54160 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology Bee... |
| CVE-2025-54159 | HIGH | 7.5 | 0.4% | Dec 4, 2025 | Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attack... |
| CVE-2025-54158 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-139... |
| CVE-2025-40266 | HIGH | 8.2 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Check the untrusted offset in FF-A memo... |
| CVE-2025-40265 | — | — | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: vfat: fix missing sb_min_blocksize() return value c... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now