2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40257 | CRITICAL | 9.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fix a race in mptcp_pm_del_add_timer() mptc... |
| CVE-2025-40252 | CRITICAL | 9.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: qlogic/qede: fix potential out-of-bounds read ... |
| CVE-2025-65346 | CRITICAL | 9.1 | 0.9% | Dec 4, 2025 | alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality ... |
| CVE-2025-54304 | CRITICAL | 9.8 | 0.4% | Dec 4, 2025 | An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. When they are powered on, an X11 dis... |
| CVE-2025-54303 | CRITICAL | 9.8 | 0.3% | Dec 4, 2025 | The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for... |
| CVE-2025-53963 | CRITICAL | 9.8 | 0.4% | Dec 4, 2025 | An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible ov... |
| CVE-2025-14004 | CRITICAL | 9.8 | 0.4% | Dec 4, 2025 | A security flaw has been discovered in dayrui XunRuiCMS up to 4.7.1. Affected is an unknown function of the file /admind... |
| CVE-2025-64055 | CRITICAL | 9.8 | 0.5% | Dec 3, 2025 | An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access admi... |
| CVE-2025-66489 | CRITICAL | 9.8 | 0.8% | Dec 3, 2025 | Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker ... |
| CVE-2025-66222 | CRITICAL | 9.6 | 0.5% | Dec 3, 2025 | DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting... |
| CVE-2025-66208 | CRITICAL | 9.8 | 0.9% | Dec 3, 2025 | Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing ... |
| CVE-2025-66032 | CRITICAL | 9.8 | 0.6% | Dec 3, 2025 | Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and shor... |
| CVE-2025-64443 | CRITICAL | 9.6 | 0.4% | Dec 3, 2025 | MCP Gateway allows easy and secure running and deployment of MCP servers. In versions 0.27.0 and earlier, when MCP Gatew... |
| CVE-2025-34319 | CRITICAL | 9.3 | 4.2% | Dec 3, 2025 | TOTOLINK N300RT wireless router firmware versions prior to V3.4.0-B20250430 (discovered in V2.1.8-B20201030.1539) contai... |
| CVE-2025-55182 | CRITICAL | 10 | 99.6% | Dec 3, 2025 | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1... |
| CVE-2025-65267 | CRITICAL | 9 | 0.3% | Dec 3, 2025 | In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to... |
| CVE-2025-13390 | CRITICAL | 9.8 | 4.7% | Dec 3, 2025 | The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1... |
| CVE-2025-13342 | CRITICAL | 9.8 | 0.4% | Dec 3, 2025 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress ... |
| CVE-2025-13486 | CRITICAL | 9.8 | 73.6% | Dec 3, 2025 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 thr... |
| CVE-2025-13658 | CRITICAL | 9.3 | 0.6% | Dec 2, 2025 | A vulnerability in Longwatch devices allows unauthenticated HTTP GET requests to execute arbitrary code via an exposed e... |
| CVE-2025-13542 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.... |
| CVE-2025-13510 | CRITICAL | 9.3 | 0.6% | Dec 2, 2025 | The Iskra iHUB and iHUB Lite smart metering gateway exposes its web management interface without requiring authenticatio... |
| CVE-2025-66409 | CRITICAL | 9.1 | 0.5% | Dec 2, 2025 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earli... |
| CVE-2025-65896 | CRITICAL | 9.8 | 0.4% | Dec 2, 2025 | SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via craf... |
| CVE-2025-60736 | CRITICAL | 9.8 | 0.4% | Dec 2, 2025 | code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now