2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67489 | CRITICAL | 9.8 | 0.7% | Dec 9, 2025 | @vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Versions 0.5.5 and below are vulnerable to ar... |
| CVE-2025-66456 | CRITICAL | 9.8 | 0.5% | Dec 9, 2025 | Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communi... |
| CVE-2025-65741 | CRITICAL | 9.8 | 0.4% | Dec 9, 2025 | Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection. An attacker could compile a .dylib file a... |
| CVE-2025-64113 | CRITICAL | 9.8 | 0.6% | Dec 9, 2025 | Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrati... |
| CVE-2025-14337 | CRITICAL | 9.8 | 0.3% | Dec 9, 2025 | A vulnerability was determined in itsourcecode Student Management System 1.0. This affects an unknown part of the file /... |
| CVE-2025-65882 | CRITICAL | 9.8 | 0.6% | Dec 9, 2025 | An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrad... |
| CVE-2025-14336 | CRITICAL | 9.8 | 0.3% | Dec 9, 2025 | A vulnerability was found in itsourcecode Student Management System 1.0. Affected by this issue is some unknown function... |
| CVE-2025-14335 | CRITICAL | 9.8 | 0.3% | Dec 9, 2025 | A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unkno... |
| CVE-2025-14334 | CRITICAL | 9.8 | 0.3% | Dec 9, 2025 | A flaw has been found in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /new_ad... |
| CVE-2025-64672 | CRITICAL | 9 | 1.0% | Dec 9, 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2025-59719 | CRITICAL | 9.8 | 23.7% | Dec 9, 2025 | An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6... |
| CVE-2025-59718 | CRITICAL | 9.8 | 65.8% | Dec 9, 2025 | A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 ... |
| CVE-2025-34414 | CRITICAL | 9.3 | 0.7% | Dec 9, 2025 | Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to... |
| CVE-2025-63742 | CRITICAL | 9.8 | 0.3% | Dec 9, 2025 | SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA ... |
| CVE-2025-67504 | CRITICAL | 9.8 | 0.4% | Dec 9, 2025 | WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwo... |
| CVE-2025-66631 | CRITICAL | 9.8 | 0.6% | Dec 9, 2025 | CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Ver... |
| CVE-2025-66568 | CRITICAL | 9.1 | 0.2% | Dec 9, 2025 | The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vuln... |
| CVE-2025-66567 | CRITICAL | 9.1 | 0.4% | Dec 9, 2025 | The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and includin... |
| CVE-2025-66565 | CRITICAL | 9.8 | 0.4% | Dec 9, 2025 | Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's c... |
| CVE-2025-42928 | CRITICAL | 9.1 | 8.0% | Dec 9, 2025 | Under certain conditions, a high privileged user could exploit a deserialization vulnerability in SAP jConnect to launch... |
| CVE-2025-42880 | CRITICAL | 9.9 | 3.9% | Dec 9, 2025 | Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when cal... |
| CVE-2025-40938 | CRITICAL | 9.8 | 0.3% | Dec 9, 2025 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive inf... |
| CVE-2025-40801 | CRITICAL | 9.2 | 0.2% | Dec 9, 2025 | A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi... |
| CVE-2025-40800 | CRITICAL | 9.1 | 0.2% | Dec 9, 2025 | A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2... |
| CVE-2025-40343 | CRITICAL | 9.8 | 0.2% | Dec 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: avoid scheduling association deletion twi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now