2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66412 | MEDIUM | 5.4 | 0.4% | Dec 1, 2025 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2025-66410 | CRITICAL | 9.1 | 0.5% | Dec 1, 2025 | Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file... |
| CVE-2025-66405 | CRITICAL | 9.8 | 0.3% | Dec 1, 2025 | Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the ... |
| CVE-2025-66403 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 2.2.3, ... |
| CVE-2025-66401 | CRITICAL | 9.8 | 2.0% | Dec 1, 2025 | MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPSca... |
| CVE-2025-66400 | MEDIUM | 5.3 | 0.3% | Dec 1, 2025 | mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classna... |
| CVE-2025-66313 | HIGH | 7.2 | 0.3% | Dec 1, 2025 | ChurchCRM is an open-source church management system. In ChurchCRM 6.2.0 and earlier, there is a time-based blind SQL in... |
| CVE-2025-66312 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ... |
| CVE-2025-66311 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ... |
| CVE-2025-66310 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ... |
| CVE-2025-66309 | MEDIUM | 6.1 | 0.2% | Dec 1, 2025 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ... |
| CVE-2025-66308 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ... |
| CVE-2025-66307 | MEDIUM | 5.3 | 0.3% | Dec 1, 2025 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ... |
| CVE-2025-66306 | MEDIUM | 6.5 | 0.3% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerabi... |
| CVE-2025-66305 | MEDIUM | 4.9 | 0.3% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Denial of Service (DoS) vulnerability was identified in the... |
| CVE-2025-66304 | HIGH | 7.2 | 0.4% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section... |
| CVE-2025-66303 | MEDIUM | 4.9 | 0.3% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A Denial of Service (DoS) vulnerability has been identified i... |
| CVE-2025-66302 | MEDIUM | 6.8 | 0.4% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CM... |
| CVE-2025-66301 | CRITICAL | 9.6 | 1.2% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical ... |
| CVE-2025-66300 | HIGH | 8.5 | 0.4% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can ... |
| CVE-2025-66299 | HIGH | 8.8 | 0.5% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (S... |
| CVE-2025-66298 | HIGH | 7.5 | 0.3% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav config... |
| CVE-2025-65622 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user ... |
| CVE-2025-66297 | HIGH | 8.8 | 0.7% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or e... |
| CVE-2025-66296 | HIGH | 8.8 | 0.3% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin p... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now