2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65657 | MEDIUM | 6.5 | 0.3% | Dec 2, 2025 | FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1... |
| CVE-2025-65380 | MEDIUM | 6.5 | 0.2% | Dec 2, 2025 | PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username... |
| CVE-2025-64778 | HIGH | 7.8 | 0.1% | Dec 2, 2025 | NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. The... |
| CVE-2025-64642 | HIGH | 7.8 | 0.1% | Dec 2, 2025 | NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which... |
| CVE-2025-64298 | HIGH | 7.5 | 0.2% | Dec 2, 2025 | NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are expose... |
| CVE-2025-62575 | HIGH | 8.8 | 0.4% | Dec 2, 2025 | NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and o... |
| CVE-2025-61940 | HIGH | 8.8 | 0.3% | Dec 2, 2025 | NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User ... |
| CVE-2025-65877 | HIGH | 7.5 | 0.3% | Dec 2, 2025 | Lvzhou CMS before commit c4ea0eb9cab5f6739b2c87e77d9ef304017ed615 (2025-09-22) is vulnerable to SQL injection via the 't... |
| CVE-2025-65379 | MEDIUM | 6.5 | 0.2% | Dec 2, 2025 | PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the /admin/password-recovery.php endpoint. Specifically,... |
| CVE-2025-13658 | CRITICAL | 9.3 | 0.6% | Dec 2, 2025 | A vulnerability in Longwatch devices allows unauthenticated HTTP GET requests to execute arbitrary code via an exposed e... |
| CVE-2025-13542 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.... |
| CVE-2025-13510 | CRITICAL | 9.3 | 0.6% | Dec 2, 2025 | The Iskra iHUB and iHUB Lite smart metering gateway exposes its web management interface without requiring authenticatio... |
| CVE-2025-66468 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior ... |
| CVE-2025-66460 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call eac... |
| CVE-2025-66459 | MEDIUM | 6.1 | 0.3% | Dec 2, 2025 | Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call eac... |
| CVE-2025-66458 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call eac... |
| CVE-2025-66454 | MEDIUM | 6.5 | 0.3% | Dec 2, 2025 | Arcade MCP allows you to to create, deploy, and share MCP Servers. Prior to 1.5.4, the arcade-mcp HTTP server uses a har... |
| CVE-2025-66416 | HIGH | 8.1 | 0.4% | Dec 2, 2025 | The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to versi... |
| CVE-2025-66414 | HIGH | 8.1 | 0.4% | Dec 2, 2025 | MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The M... |
| CVE-2025-66409 | CRITICAL | 9.1 | 0.5% | Dec 2, 2025 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earli... |
| CVE-2025-65896 | CRITICAL | 9.8 | 0.4% | Dec 2, 2025 | SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via craf... |
| CVE-2025-61729 | HIGH | 7.5 | 0.5% | Dec 2, 2025 | Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be p... |
| CVE-2025-60736 | CRITICAL | 9.8 | 0.4% | Dec 2, 2025 | code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter. |
| CVE-2025-57850 | MEDIUM | 6.4 | 0.2% | Dec 2, 2025 | A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/p... |
| CVE-2025-34352 | HIGH | 8.5 | 0.2% | Dec 2, 2025 | JumpCloud Remote Assist for Windows versions prior to 0.317.0 include an uninstaller that is invoked by the JumpCloud Wi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now