2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13721 | HIGH | 7.5 | 0.2% | Dec 2, 2025 | Race in v8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via ... |
| CVE-2025-13720 | HIGH | 8.8 | 0.2% | Dec 2, 2025 | Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer pr... |
| CVE-2025-13640 | LOW | 3.5 | 0.2% | Dec 2, 2025 | Inappropriate implementation in Passwords in Google Chrome prior to 143.0.7499.41 allowed a local attacker to bypass aut... |
| CVE-2025-13639 | HIGH | 8.1 | 0.2% | Dec 2, 2025 | Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbi... |
| CVE-2025-13638 | HIGH | 8.8 | 0.2% | Dec 2, 2025 | Use after free in Media Stream in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit ... |
| CVE-2025-13637 | MEDIUM | 4.3 | 0.2% | Dec 2, 2025 | Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convince... |
| CVE-2025-13636 | MEDIUM | 4.3 | 0.2% | Dec 2, 2025 | Inappropriate implementation in Split View in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinc... |
| CVE-2025-13635 | MEDIUM | 4.4 | 0.1% | Dec 2, 2025 | Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a local attacker to perform UI... |
| CVE-2025-13634 | MEDIUM | 4.4 | 0.1% | Dec 2, 2025 | Inappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41 allowed a local attacker to... |
| CVE-2025-13633 | HIGH | 8.8 | 0.4% | Dec 2, 2025 | Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromi... |
| CVE-2025-13632 | MEDIUM | 5.4 | 0.2% | Dec 2, 2025 | Inappropriate implementation in DevTools in Google Chrome prior to 143.0.7499.41 allowed an attacker who convinced a use... |
| CVE-2025-13631 | HIGH | 8.8 | 0.3% | Dec 2, 2025 | Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowed a remote attacker ... |
| CVE-2025-13630 | HIGH | 8.8 | 0.4% | Dec 2, 2025 | Type Confusion in V8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2025-66399 | HIGH | 8.8 | 10.8% | Dec 2, 2025 | Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw i... |
| CVE-2025-65881 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | Sourcecodester Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /classes/Login.php. |
| CVE-2025-65844 | HIGH | 7.5 | 0.3% | Dec 2, 2025 | EverShop 2.0.1 allows a remote unauthenticated attacker to upload arbitrary files and create directories via the /api/im... |
| CVE-2025-65215 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | Sourcecodester Web-based Pharmacy Product Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /product... |
| CVE-2025-65105 | MEDIUM | 5.3 | 0.2% | Dec 2, 2025 | Apptainer is an open source container platform. In Apptainer versions less than 1.4.5, a container can disable two of th... |
| CVE-2025-64750 | MEDIUM | 4.5 | 0.1% | Dec 2, 2025 | SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.3.5 and SingularityPRO 4.... |
| CVE-2025-60854 | CRITICAL | 9.8 | 1.0% | Dec 2, 2025 | A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during... |
| CVE-2025-58386 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper serv... |
| CVE-2025-52622 | MEDIUM | 5.4 | 0.1% | Dec 2, 2025 | The BigFix SaaS's HTTP responses were missing some security headers. The absence of these headers weakens the applicatio... |
| CVE-2025-65656 | CRITICAL | 9.8 | 0.4% | Dec 2, 2025 | dcat-admin v2.2.3-beta and before is vulnerable to file inclusion in admin/src/Extend/VersionManager.php. |
| CVE-2025-65358 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain SQl injection vulnerability via the 'docid' parameter at... |
| CVE-2025-65186 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page con... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now