2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66295 | HIGH | 8.8 | 0.5% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new use... |
| CVE-2025-66294 | HIGH | 8.8 | 2.6% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists ... |
| CVE-2025-66206 | HIGH | 8.6 | 0.3% | Dec 1, 2025 | Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, certain requests were vulnerable to path... |
| CVE-2025-66205 | CRITICAL | 9.8 | 0.3% | Dec 1, 2025 | Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to err... |
| CVE-2025-65840 | HIGH | 8.8 | 0.1% | Dec 1, 2025 | PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController. |
| CVE-2025-65621 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes... |
| CVE-2025-58044 | MEDIUM | 6.1 | 0.4% | Dec 1, 2025 | JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and ... |
| CVE-2025-55749 | HIGH | 7.5 | 1.4% | Dec 1, 2025 | XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is usin... |
| CVE-2025-65838 | HIGH | 7.5 | 0.4% | Dec 1, 2025 | PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method. |
| CVE-2025-65836 | CRITICAL | 9.1 | 0.3% | Dec 1, 2025 | PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController. |
| CVE-2025-63317 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | Todoist v8896 is vulnerable to Cross Site Scripting (XSS) in /api/v1/uploads. Uploaded SVG files have no sanitization ap... |
| CVE-2025-51683 | CRITICAL | 9.8 | 0.4% | Dec 1, 2025 | A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL... |
| CVE-2025-51682 | CRITICAL | 9.8 | 0.4% | Dec 1, 2025 | mJobtime 15.7.2 handles authorization on the client side, which allows an attacker to modify the client-side code and ga... |
| CVE-2025-12756 | MEDIUM | 4.3 | 0.2% | Dec 1, 2025 | Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user pe... |
| CVE-2025-65407 | MEDIUM | 6.5 | 0.2% | Dec 1, 2025 | A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows atta... |
| CVE-2025-63365 | HIGH | 7.1 | 0.3% | Dec 1, 2025 | SoftSea EPUB File Reader 1.0.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the EPUB file proces... |
| CVE-2025-34297 | HIGH | 8.6 | 0.1% | Dec 1, 2025 | KissFFT versions prior to the fix commit 1b083165 contain an integer overflow in kiss_fft_alloc() in kiss_fft.c on platf... |
| CVE-2025-11772 | MEDIUM | 6.6 | 0.1% | Dec 1, 2025 | A carefully crafted DLL, copied to C:\ProgramData\Synaptics folder, allows a local user to execute arbitrary code w... |
| CVE-2025-13837 | MEDIUM | 5.5 | 0.2% | Dec 1, 2025 | When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file... |
| CVE-2025-13836 | HIGH | 7.5 | 1.5% | Dec 1, 2025 | When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content... |
| CVE-2025-13835 | MEDIUM | 6.5 | 0.1% | Dec 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arc... |
| CVE-2025-13653 | MEDIUM | 4.3 | 0.2% | Dec 1, 2025 | In Search Guard FLX versions from 3.1.0 up to 4.0.0 with enterprise modules being disabled, there exists an issue which ... |
| CVE-2025-7007 | HIGH | 7.5 | 0.1% | Dec 1, 2025 | NULL Pointer Dereference vulnerability in Avast Antivirus on MacOS, Avast Anitvirus on Linux when scanning a malformed W... |
| CVE-2025-65794 | — | — | — | Dec 1, 2025 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2025-65793 | — | — | — | Dec 1, 2025 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now