2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54305 | HIGH | 7.8 | 0.1% | Dec 4, 2025 | An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the middlewares included in... |
| CVE-2025-54304 | CRITICAL | 9.8 | 0.4% | Dec 4, 2025 | An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. When they are powered on, an X11 dis... |
| CVE-2025-54303 | CRITICAL | 9.8 | 0.3% | Dec 4, 2025 | The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for... |
| CVE-2025-53963 | CRITICAL | 9.8 | 0.4% | Dec 4, 2025 | An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible ov... |
| CVE-2025-40221 | — | — | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: media: pci: mg4b: fix uninitialized iio scan data ... |
| CVE-2025-40220 | — | — | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: fuse: fix livelock in synchronous file put from fus... |
| CVE-2025-40219 | — | — | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: PCI/IOV: Fix race between SR-IOV enable/disable and... |
| CVE-2025-40218 | — | — | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/vaddr: do not repeat pte_offset_map_lock()... |
| CVE-2025-40217 | — | — | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: pidfs: validate extensible ioctls Validate extensi... |
| CVE-2025-40216 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: don't rely on user vaddr alignment ... |
| CVE-2025-2848 | MEDIUM | 6.3 | 0.4% | Dec 4, 2025 | A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, ... |
| CVE-2025-29846 | HIGH | 7.2 | 0.6% | Dec 4, 2025 | A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages. |
| CVE-2025-29845 | MEDIUM | 4.3 | 0.4% | Dec 4, 2025 | A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files. |
| CVE-2025-29844 | MEDIUM | 4.3 | 0.4% | Dec 4, 2025 | A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information. |
| CVE-2025-29843 | MEDIUM | 5.4 | 0.3% | Dec 4, 2025 | A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files. |
| CVE-2025-14008 | HIGH | 7.2 | 0.3% | Dec 4, 2025 | A flaw has been found in dayrui XunRuiCMS up to 4.7.1. This vulnerability affects unknown code of the file admin79f2ec22... |
| CVE-2025-14007 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | A vulnerability was detected in dayrui XunRuiCMS up to 4.7.1. This affects an unknown part of the file /admin79f2ec220c7... |
| CVE-2025-14006 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | A security vulnerability has been detected in dayrui XunRuiCMS up to 4.7.1. Affected by this issue is some unknown funct... |
| CVE-2025-14005 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | A weakness has been identified in dayrui XunRuiCMS up to 4.7.1. Affected by this vulnerability is an unknown functionali... |
| CVE-2025-14004 | CRITICAL | 9.8 | 0.4% | Dec 4, 2025 | A security flaw has been discovered in dayrui XunRuiCMS up to 4.7.1. Affected is an unknown function of the file /admind... |
| CVE-2025-40215 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: xfrm: delete x->tunnel as we delete x The ipcomp f... |
| CVE-2025-40214 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). ... |
| CVE-2025-11222 | MEDIUM | 6.1 | 0.1% | Dec 4, 2025 | Central Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to u... |
| CVE-2025-41080 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attac... |
| CVE-2025-41079 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attac... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now