2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65826 | CRITICAL | 9.8 | 0.2% | Dec 10, 2025 | The mobile application was found to contain stored credentials for the network it was developed on. If an attacker retri... |
| CVE-2025-65823 | CRITICAL | 9.8 | — | Dec 10, 2025 | The Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was d... |
| CVE-2025-65820 | CRITICAL | 9.8 | 0.4% | Dec 10, 2025 | An issue was discovered in Meatmeet Android Mobile Application 1.1.2.0. An exported activity can be spawned with the mob... |
| CVE-2025-65602 | CRITICAL | 9.8 | 0.5% | Dec 10, 2025 | A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbi... |
| CVE-2025-64539 | CRITICAL | 9.3 | 0.5% | Dec 10, 2025 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2025-64538 | CRITICAL | 9.3 | 0.6% | Dec 10, 2025 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2025-64537 | CRITICAL | 9.3 | 0.7% | Dec 10, 2025 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2025-13607 | CRITICAL | 9.4 | 0.8% | Dec 10, 2025 | A malicious actor can access camera configuration information, including account credentials, without authenticating whe... |
| CVE-2025-65792 | CRITICAL | 9.1 | 0.4% | Dec 10, 2025 | DataGear v5.5.0 is vulnerable to Arbitrary File Deletion. |
| CVE-2025-34394 | CRITICAL | 9.8 | 0.6% | Dec 10, 2025 | Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting ser... |
| CVE-2025-34393 | CRITICAL | 9.8 | 0.6% | Dec 10, 2025 | Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify t... |
| CVE-2025-34392 | CRITICAL | 9.8 | 22.0% | Dec 10, 2025 | Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL def... |
| CVE-2025-13184 | CRITICAL | 9.8 | 11.3% | Dec 10, 2025 | Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank passw... |
| CVE-2025-13953 | CRITICAL | 9.3 | 0.4% | Dec 10, 2025 | Bypass vulnerability in the authentication method in the GTT Tax Information System application, related to the Active D... |
| CVE-2025-41732 | CRITICAL | 9.8 | 0.4% | Dec 10, 2025 | An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary d... |
| CVE-2025-41730 | CRITICAL | 9.8 | 0.4% | Dec 10, 2025 | An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary ... |
| CVE-2025-14087 | CRITICAL | 9.8 | — | Dec 10, 2025 | A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a... |
| CVE-2025-13955 | CRITICAL | 9.3 | 0.2% | Dec 10, 2025 | Predictable default Wi-Fi Password in Access Point functionality in EZCast Pro II before version 1.17478.177 allows atta... |
| CVE-2025-13954 | CRITICAL | 9.3 | 0.2% | Dec 10, 2025 | Hard-coded cryptographic keys in Admin UI of EZCast Pro II before version 1.17478.177 allows attackers to bypass authori... |
| CVE-2025-13613 | CRITICAL | 9.8 | 0.4% | Dec 10, 2025 | The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, ... |
| CVE-2025-67506 | CRITICAL | 9.8 | 1.6% | Dec 10, 2025 | PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.... |
| CVE-2025-61811 | CRITICAL | 9.1 | 1.2% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that c... |
| CVE-2025-61809 | CRITICAL | 9.1 | 0.7% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that... |
| CVE-2025-61808 | CRITICAL | 9.1 | 10.6% | Dec 10, 2025 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous T... |
| CVE-2025-66039 | CRITICAL | 9.8 | 3.3% | Dec 9, 2025 | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to aut... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now