2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14199 | CRITICAL | 9.8 | 0.3% | Dec 7, 2025 | A flaw has been found in Verysync 微力同步 up to 2.21.3. This impacts an unknown function of the file /rest/f/api/resources/... |
| CVE-2025-14191 | CRITICAL | 9.8 | 0.7% | Dec 7, 2025 | A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. Affected by this issue is the function strcpy of the f... |
| CVE-2025-14182 | CRITICAL | 9.8 | 0.4% | Dec 7, 2025 | A vulnerability has been found in Sobey Media Convergence System 2.0/2.1. This vulnerability affects unknown code of the... |
| CVE-2025-14141 | CRITICAL | 9.8 | 0.7% | Dec 6, 2025 | A flaw has been found in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formA... |
| CVE-2025-12673 | CRITICAL | 9.8 | 0.6% | Dec 6, 2025 | The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat... |
| CVE-2025-66644 | CRITICAL | 9.8 | 3.0% | Dec 5, 2025 | Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2... |
| CVE-2025-66570 | CRITICAL | 9.8 | 0.3% | Dec 5, 2025 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allow... |
| CVE-2025-66562 | CRITICAL | 9.6 | 0.4% | Dec 5, 2025 | TUUI is a desktop MCP client designed as a tool unitary utility integration. Prior to 1.3.4, a critical Remote Code Exec... |
| CVE-2025-34256 | CRITICAL | 9.8 | 0.6% | Dec 5, 2025 | Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product u... |
| CVE-2025-14094 | CRITICAL | 9.8 | 17.9% | Dec 5, 2025 | A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4 of the file /boafrm... |
| CVE-2025-14093 | CRITICAL | 9.8 | 17.3% | Dec 5, 2025 | A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub_416990 of the file /boafrm/form... |
| CVE-2025-64054 | CRITICAL | 9.6 | 0.4% | Dec 5, 2025 | A reflected Cross Site Scripting (XSS) vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial o... |
| CVE-2025-12374 | CRITICAL | 9.8 | 0.4% | Dec 5, 2025 | The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plu... |
| CVE-2025-13313 | CRITICAL | 9.8 | 0.5% | Dec 5, 2025 | The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to,... |
| CVE-2025-66509 | CRITICAL | 9.8 | 0.3% | Dec 4, 2025 | LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow tr... |
| CVE-2025-66576 | CRITICAL | 9.8 | 1.1% | Dec 4, 2025 | Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function... |
| CVE-2025-66571 | CRITICAL | 9.3 | 0.5% | Dec 4, 2025 | UNA CMS versions 9.0.0-RC1 - 14.0.0-RC4 contain a PHP object injection vulnerability in BxBaseMenuSetAclLevel.php where ... |
| CVE-2025-29269 | CRITICAL | 9.8 | 1.9% | Dec 4, 2025 | ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in t... |
| CVE-2025-29268 | CRITICAL | 9.8 | 8.1% | Dec 4, 2025 | ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library. |
| CVE-2025-12995 | CRITICAL | 9.8 | 0.3% | Dec 4, 2025 | Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint ... |
| CVE-2025-63362 | CRITICAL | 9.8 | 0.5% | Dec 4, 2025 | Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.00... |
| CVE-2025-14015 | CRITICAL | 9.8 | 0.7% | Dec 4, 2025 | A weakness has been identified in H3C Magic B0 up to 100R002. This impacts the function EditWlanMacList of the file /gof... |
| CVE-2025-66516 | CRITICAL | 9.8 | 79.8% | Dec 4, 2025 | Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules... |
| CVE-2025-40261 | CRITICAL | 9.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: nvme: nvme-fc: Ensure ->ioerr_work is cancelled in ... |
| CVE-2025-40258 | CRITICAL | 9.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fix race condition in mptcp_schedule_work() ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now