2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14245 | CRITICAL | 9.8 | 0.3% | Dec 8, 2025 | A vulnerability has been found in IdeaCMS up to 1.8. This affects the function whereRaw of the file app/common/logic/ind... |
| CVE-2025-27020 | CRITICAL | 9.8 | 0.5% | Dec 8, 2025 | Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary comm... |
| CVE-2025-27019 | CRITICAL | 9.8 | 0.4% | Dec 8, 2025 | Remote shell service (RSH) in Infinera MTC-9 version R22.1.1.0275 allows an attacker to utilize password-less user acco... |
| CVE-2025-14227 | CRITICAL | 9.8 | 0.3% | Dec 8, 2025 | A security flaw has been discovered in Philipinho Simple-PHP-Blog up to 94b5d3e57308bce5dfbc44c3edafa9811893d958. This i... |
| CVE-2025-14226 | CRITICAL | 9.8 | 0.3% | Dec 8, 2025 | A vulnerability was identified in itsourcecode Student Management System 1.0. This vulnerability affects unknown code of... |
| CVE-2025-14224 | CRITICAL | 9.8 | 0.6% | Dec 8, 2025 | A vulnerability was found in Yottamaster DM2, DM3 and DM200 up to 1.2.23/1.9.12. Affected by this issue is some unknown ... |
| CVE-2025-14223 | CRITICAL | 9.8 | 0.3% | Dec 8, 2025 | A vulnerability has been found in code-projects Simple Leave Manager 1.0. Affected by this vulnerability is an unknown f... |
| CVE-2025-14218 | CRITICAL | 9.8 | 0.3% | Dec 8, 2025 | A security flaw has been discovered in code-projects Currency Exchange System 1.0. The affected element is an unknown fu... |
| CVE-2025-14217 | CRITICAL | 9.8 | 0.3% | Dec 8, 2025 | A vulnerability was identified in code-projects Currency Exchange System 1.0. Impacted is an unknown function of the fil... |
| CVE-2025-14216 | CRITICAL | 9.8 | 0.3% | Dec 8, 2025 | A vulnerability was determined in code-projects Currency Exchange System 1.0. This issue affects some unknown processing... |
| CVE-2025-14215 | CRITICAL | 9.8 | 0.3% | Dec 8, 2025 | A vulnerability was found in code-projects Currency Exchange System 1.0. This vulnerability affects unknown code of the ... |
| CVE-2025-14212 | CRITICAL | 9.8 | 0.3% | Dec 8, 2025 | A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown fu... |
| CVE-2025-14211 | CRITICAL | 9.8 | 0.3% | Dec 8, 2025 | A vulnerability was detected in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is ... |
| CVE-2025-14210 | CRITICAL | 9.8 | 0.3% | Dec 8, 2025 | A security vulnerability has been detected in projectworlds Advanced Library Management System 1.0. Affected is an unkno... |
| CVE-2025-14209 | CRITICAL | 9.8 | 0.3% | Dec 8, 2025 | A weakness has been identified in Campcodes School File Management System 1.0. This impacts an unknown function of the f... |
| CVE-2025-40320 | CRITICAL | 9.8 | 0.2% | Dec 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential cfid UAF in smb2_query_i... |
| CVE-2025-14199 | CRITICAL | 9.8 | 0.3% | Dec 7, 2025 | A flaw has been found in Verysync 微力同步 up to 2.21.3. This impacts an unknown function of the file /rest/f/api/resources/... |
| CVE-2025-14191 | CRITICAL | 9.8 | 0.7% | Dec 7, 2025 | A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. Affected by this issue is the function strcpy of the f... |
| CVE-2025-14182 | CRITICAL | 9.8 | 0.4% | Dec 7, 2025 | A vulnerability has been found in Sobey Media Convergence System 2.0/2.1. This vulnerability affects unknown code of the... |
| CVE-2025-14141 | CRITICAL | 9.8 | 0.7% | Dec 6, 2025 | A flaw has been found in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formA... |
| CVE-2025-12673 | CRITICAL | 9.8 | 0.6% | Dec 6, 2025 | The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat... |
| CVE-2025-66644 | CRITICAL | 9.8 | 3.0% | Dec 5, 2025 | Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2... |
| CVE-2025-66570 | CRITICAL | 9.8 | 0.3% | Dec 5, 2025 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allow... |
| CVE-2025-66562 | CRITICAL | 9.6 | 0.5% | Dec 5, 2025 | TUUI is a desktop MCP client designed as a tool unitary utility integration. Prior to 1.3.4, a critical Remote Code Exec... |
| CVE-2025-34256 | CRITICAL | 9.8 | 0.6% | Dec 5, 2025 | Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product u... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now