2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13829 | HIGH | 8.6 | 0.3% | Dec 1, 2025 | Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private... |
| CVE-2025-11699 | HIGH | 7.1 | 0.4% | Dec 1, 2025 | nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination... |
| CVE-2025-10101 | HIGH | 7.8 | 0.1% | Dec 1, 2025 | Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Mach-O file may allow Local Ex... |
| CVE-2025-64030 | MEDIUM | 5.4 | 0.2% | Dec 1, 2025 | Eximbills Enterprise 4.1.5 (Built on 2020-10-30) is vulnerable to authenticated stored cross-site scripting (CWE-79) via... |
| CVE-2025-63531 | CRITICAL | 9.8 | 0.6% | Dec 1, 2025 | A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The... |
| CVE-2025-63529 | HIGH | 8.8 | 0.3% | Dec 1, 2025 | A session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set ... |
| CVE-2025-63528 | MEDIUM | 5.4 | 0.3% | Dec 1, 2025 | A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the blooddinfo.php comp... |
| CVE-2025-63527 | MEDIUM | 5.4 | 0.3% | Dec 1, 2025 | A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php a... |
| CVE-2025-63526 | MEDIUM | 5.4 | 0.3% | Dec 1, 2025 | A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System within the abs.php component. The ... |
| CVE-2025-63525 | HIGH | 8.8 | 0.4% | Dec 1, 2025 | An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with esc... |
| CVE-2025-63523 | MEDIUM | 6.5 | 0.2% | Dec 1, 2025 | FeehiCMS version 2.1.1 fails to enforce server-side immutability for parameters that are presented to clients as "read-o... |
| CVE-2025-63522 | MEDIUM | 4.6 | 0.2% | Dec 1, 2025 | Reverse Tabnabbing vulnerability in FeehiCMS 2.1.1 in the Comments Management function |
| CVE-2025-63520 | MEDIUM | 6.1 | 0.2% | Dec 1, 2025 | Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 via the id parameter of the User Update function (?r=user%2Fu... |
| CVE-2025-13129 | MEDIUM | 4.3 | 0.2% | Dec 1, 2025 | Improper Enforcement of Behavioral Workflow vulnerability in Seneka Software Hardware Information Technology Trade Contr... |
| CVE-2025-49643 | MEDIUM | 6.5 | 0.3% | Dec 1, 2025 | An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending sp... |
| CVE-2025-49642 | MEDIUM | 5.9 | 0.1% | Dec 1, 2025 | Library loading on AIX Zabbix Agent builds can be hijacked by local users with write access to the /home/cecuser directo... |
| CVE-2025-27232 | MEDIUM | 4.9 | 0.3% | Dec 1, 2025 | An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver le... |
| CVE-2025-12106 | CRITICAL | 9.1 | 0.5% | Dec 1, 2025 | Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-... |
| CVE-2025-58408 | MEDIUM | 5.9 | 0.1% | Dec 1, 2025 | Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger reads of stale data... |
| CVE-2025-13296 | MEDIUM | 5.4 | 0.1% | Dec 1, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Tekrom Technology Inc. T-Soft E-Commerce allows Cross Site Request Fo... |
| CVE-2025-8045 | MEDIUM | 4 | 0.2% | Dec 1, 2025 | Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver al... |
| CVE-2025-6349 | MEDIUM | 5.1 | 0.2% | Dec 1, 2025 | Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver al... |
| CVE-2025-59789 | HIGH | 7.5 | 1.5% | Dec 1, 2025 | Uncontrolled recursion in the json2pb component in Apache bRPC (version < 1.15.0) on all platforms allows remote attacke... |
| CVE-2025-41070 | MEDIUM | 4.8 | 0.2% | Dec 1, 2025 | Reflected Cross-site Scripting (XSS) vulnerability in Sanoma's Clickedu. This vulnerability allows an attacker to execut... |
| CVE-2025-2879 | MEDIUM | 5.1 | 0.1% | Dec 1, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd A... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now