2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14265 | CRITICAL | 9.1 | 0.3% | Dec 11, 2025 | In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem ... |
| CVE-2025-14515 | CRITICAL | 9.8 | 0.3% | Dec 11, 2025 | A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected by this vulnerability is an unknown... |
| CVE-2025-14514 | CRITICAL | 9.8 | 0.4% | Dec 11, 2025 | A flaw has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/ad... |
| CVE-2025-13764 | CRITICAL | 9.8 | 0.3% | Dec 11, 2025 | The WP CarDealer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.16... |
| CVE-2025-67511 | CRITICAL | 9.6 | 1.8% | Dec 11, 2025 | Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automat... |
| CVE-2025-67510 | CRITICAL | 9.4 | 0.3% | Dec 10, 2025 | Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool exe... |
| CVE-2025-65294 | CRITICAL | 9.8 | 0.8% | Dec 10, 2025 | Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented r... |
| CVE-2025-65830 | CRITICAL | 9.1 | 0.2% | Dec 10, 2025 | Due to a lack of certificate validation, all traffic from the mobile application can be intercepted. As a result, an adv... |
| CVE-2025-65827 | CRITICAL | 9.1 | 0.2% | Dec 10, 2025 | The mobile application is configured to allow clear text traffic to all domains and communicates with an API server over... |
| CVE-2025-65826 | CRITICAL | 9.8 | 0.2% | Dec 10, 2025 | The mobile application was found to contain stored credentials for the network it was developed on. If an attacker retri... |
| CVE-2025-65823 | CRITICAL | 9.8 | 0.4% | Dec 10, 2025 | The Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was d... |
| CVE-2025-65820 | CRITICAL | 9.8 | 0.4% | Dec 10, 2025 | An issue was discovered in Meatmeet Android Mobile Application 1.1.2.0. An exported activity can be spawned with the mob... |
| CVE-2025-65602 | CRITICAL | 9.8 | 0.5% | Dec 10, 2025 | A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbi... |
| CVE-2025-64539 | CRITICAL | 9.3 | 0.4% | Dec 10, 2025 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2025-64538 | CRITICAL | 9.3 | 0.5% | Dec 10, 2025 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2025-64537 | CRITICAL | 9.3 | 0.7% | Dec 10, 2025 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2025-13607 | CRITICAL | 9.4 | 0.8% | Dec 10, 2025 | A malicious actor can access camera configuration information, including account credentials, without authenticating whe... |
| CVE-2025-65792 | CRITICAL | 9.1 | 0.4% | Dec 10, 2025 | DataGear v5.5.0 is vulnerable to Arbitrary File Deletion. |
| CVE-2025-34394 | CRITICAL | 9.8 | 0.6% | Dec 10, 2025 | Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting ser... |
| CVE-2025-34393 | CRITICAL | 9.8 | 0.6% | Dec 10, 2025 | Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify t... |
| CVE-2025-34392 | CRITICAL | 9.8 | 22.0% | Dec 10, 2025 | Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL def... |
| CVE-2025-13184 | CRITICAL | 9.8 | 11.0% | Dec 10, 2025 | Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank passw... |
| CVE-2025-13953 | CRITICAL | 9.3 | 0.4% | Dec 10, 2025 | Bypass vulnerability in the authentication method in the GTT Tax Information System application, related to the Active D... |
| CVE-2025-41732 | CRITICAL | 9.8 | 0.4% | Dec 10, 2025 | An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary d... |
| CVE-2025-41730 | CRITICAL | 9.8 | 0.4% | Dec 10, 2025 | An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now