2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66208 | CRITICAL | 9.8 | 0.9% | Dec 3, 2025 | Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing ... |
| CVE-2025-66032 | CRITICAL | 9.8 | 0.6% | Dec 3, 2025 | Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and shor... |
| CVE-2025-63402 | MEDIUM | 5.5 | 0.3% | Dec 3, 2025 | An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code vi... |
| CVE-2025-63401 | MEDIUM | 5.5 | 0.3% | Dec 3, 2025 | Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to... |
| CVE-2025-50360 | HIGH | 8.4 | 0.2% | Dec 3, 2025 | A heap buffer overflow in compiler.c and compiler.h in Pepper language 0.1.1commit 961a5d9988c5986d563310275adad3fd181b2... |
| CVE-2025-33211 | HIGH | 7.5 | 0.6% | Dec 3, 2025 | NVIDIA Triton Server for Linux contains a vulnerability where an attacker may cause an improper validation of specified ... |
| CVE-2025-33208 | HIGH | 8.8 | 0.4% | Dec 3, 2025 | NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path.... |
| CVE-2025-33201 | HIGH | 7.5 | 0.8% | Dec 3, 2025 | NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause an improper check for unusual or exc... |
| CVE-2025-13992 | MEDIUM | 4.7 | 0.2% | Dec 3, 2025 | Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote atta... |
| CVE-2025-12819 | HIGH | 8.1 | 0.3% | Dec 3, 2025 | Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to ... |
| CVE-2025-12084 | MEDIUM | 5.3 | 0.7% | Dec 3, 2025 | When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_ca... |
| CVE-2025-66478 | — | — | — | Dec 3, 2025 | Rejected reason: This CVE is a duplicate of CVE-2025-55182. |
| CVE-2025-64763 | MEDIUM | 5.3 | 0.3% | Dec 3, 2025 | Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, when Envoy is c... |
| CVE-2025-64527 | MEDIUM | 6.5 | 0.5% | Dec 3, 2025 | Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy crashes w... |
| CVE-2025-64443 | CRITICAL | 9.6 | 0.4% | Dec 3, 2025 | MCP Gateway allows easy and secure running and deployment of MCP servers. In versions 0.27.0 and earlier, when MCP Gatew... |
| CVE-2025-66431 | HIGH | 7.8 | 0.2% | Dec 3, 2025 | WebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remote authenticated users to execute arbitr... |
| CVE-2025-65843 | HIGH | 7.7 | 0.2% | Dec 3, 2025 | Aquarius Desktop 3.0.069 for macOS contains an insecure file handling vulnerability in its support data archive generati... |
| CVE-2025-65842 | MEDIUM | 5.1 | 0.1% | Dec 3, 2025 | The Aquarius HelperTool (1.0.003) privileged XPC service on macOS contains multiple flaws that allow local privilege esc... |
| CVE-2025-65841 | MEDIUM | 6.2 | 0.2% | Dec 3, 2025 | Aquarius Desktop 3.0.069 for macOS stores user authentication credentials in the local file ~/Library/Application Suppor... |
| CVE-2025-62686 | MEDIUM | 6.2 | 0.2% | Dec 3, 2025 | A local privilege escalation vulnerability exists in the Plugin Alliance InstallationHelper service included with Plugin... |
| CVE-2025-55076 | MEDIUM | 6.2 | 0.2% | Dec 3, 2025 | A local privilege escalation vulnerability exists in the InstallationHelper service included with Plugin Alliance Instal... |
| CVE-2025-54326 | HIGH | 7.5 | 0.3% | Dec 3, 2025 | An issue was discovered in Camera in Samsung Mobile Processor Exynos 1280 and 2200. Unnecessary registration of a hardwa... |
| CVE-2025-54065 | HIGH | 7.9 | 0.1% | Dec 3, 2025 | GZDoom is a feature centric port for all Doom engine games. GZDoom is an open source Doom engine. In versions 4.14.2 and... |
| CVE-2025-53965 | MEDIUM | 5.3 | 0.2% | Dec 3, 2025 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 220... |
| CVE-2025-34319 | CRITICAL | 9.3 | 4.2% | Dec 3, 2025 | TOTOLINK N300RT wireless router firmware versions prior to V3.4.0-B20250430 (discovered in V2.1.8-B20201030.1539) contai... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now