2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14094 | CRITICAL | 9.8 | 17.9% | Dec 5, 2025 | A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4 of the file /boafrm... |
| CVE-2025-14093 | CRITICAL | 9.8 | 17.3% | Dec 5, 2025 | A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub_416990 of the file /boafrm/form... |
| CVE-2025-64054 | CRITICAL | 9.6 | 0.4% | Dec 5, 2025 | A reflected Cross Site Scripting (XSS) vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial o... |
| CVE-2025-12374 | CRITICAL | 9.8 | 0.4% | Dec 5, 2025 | The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plu... |
| CVE-2025-13313 | CRITICAL | 9.8 | 0.5% | Dec 5, 2025 | The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to,... |
| CVE-2025-66509 | CRITICAL | 9.8 | 0.3% | Dec 4, 2025 | LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow tr... |
| CVE-2025-66576 | CRITICAL | 9.8 | 1.1% | Dec 4, 2025 | Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function... |
| CVE-2025-66571 | CRITICAL | 9.3 | 0.5% | Dec 4, 2025 | UNA CMS versions 9.0.0-RC1 - 14.0.0-RC4 contain a PHP object injection vulnerability in BxBaseMenuSetAclLevel.php where ... |
| CVE-2025-29269 | CRITICAL | 9.8 | 1.9% | Dec 4, 2025 | ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in t... |
| CVE-2025-29268 | CRITICAL | 9.8 | 8.1% | Dec 4, 2025 | ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library. |
| CVE-2025-12995 | CRITICAL | 9.8 | 0.3% | Dec 4, 2025 | Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint ... |
| CVE-2025-63362 | CRITICAL | 9.8 | 0.5% | Dec 4, 2025 | Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.00... |
| CVE-2025-14015 | CRITICAL | 9.8 | 0.7% | Dec 4, 2025 | A weakness has been identified in H3C Magic B0 up to 100R002. This impacts the function EditWlanMacList of the file /gof... |
| CVE-2025-66516 | CRITICAL | 9.8 | 79.8% | Dec 4, 2025 | Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules... |
| CVE-2025-40261 | CRITICAL | 9.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: nvme: nvme-fc: Ensure ->ioerr_work is cancelled in ... |
| CVE-2025-40258 | CRITICAL | 9.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fix race condition in mptcp_schedule_work() ... |
| CVE-2025-40257 | CRITICAL | 9.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fix a race in mptcp_pm_del_add_timer() mptc... |
| CVE-2025-40252 | CRITICAL | 9.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: qlogic/qede: fix potential out-of-bounds read ... |
| CVE-2025-65346 | CRITICAL | 9.1 | 0.9% | Dec 4, 2025 | alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality ... |
| CVE-2025-54304 | CRITICAL | 9.8 | 0.4% | Dec 4, 2025 | An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. When they are powered on, an X11 dis... |
| CVE-2025-54303 | CRITICAL | 9.8 | 0.3% | Dec 4, 2025 | The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for... |
| CVE-2025-53963 | CRITICAL | 9.8 | 0.4% | Dec 4, 2025 | An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible ov... |
| CVE-2025-14004 | CRITICAL | 9.8 | 0.4% | Dec 4, 2025 | A security flaw has been discovered in dayrui XunRuiCMS up to 4.7.1. Affected is an unknown function of the file /admind... |
| CVE-2025-64055 | CRITICAL | 9.8 | 0.5% | Dec 3, 2025 | An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access admi... |
| CVE-2025-66489 | CRITICAL | 9.8 | 0.8% | Dec 3, 2025 | Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now