2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66222 | CRITICAL | 9.6 | 0.5% | Dec 3, 2025 | DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting... |
| CVE-2025-66208 | CRITICAL | 9.8 | 0.9% | Dec 3, 2025 | Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing ... |
| CVE-2025-66032 | CRITICAL | 9.8 | 0.6% | Dec 3, 2025 | Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and shor... |
| CVE-2025-64443 | CRITICAL | 9.6 | 0.4% | Dec 3, 2025 | MCP Gateway allows easy and secure running and deployment of MCP servers. In versions 0.27.0 and earlier, when MCP Gatew... |
| CVE-2025-34319 | CRITICAL | 9.3 | 4.2% | Dec 3, 2025 | TOTOLINK N300RT wireless router firmware versions prior to V3.4.0-B20250430 (discovered in V2.1.8-B20201030.1539) contai... |
| CVE-2025-55182 | CRITICAL | 10 | 99.6% | Dec 3, 2025 | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1... |
| CVE-2025-65267 | CRITICAL | 9 | 0.3% | Dec 3, 2025 | In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to... |
| CVE-2025-13390 | CRITICAL | 9.8 | 4.7% | Dec 3, 2025 | The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1... |
| CVE-2025-13342 | CRITICAL | 9.8 | 0.4% | Dec 3, 2025 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress ... |
| CVE-2025-13486 | CRITICAL | 9.8 | 73.6% | Dec 3, 2025 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 thr... |
| CVE-2025-13658 | CRITICAL | 9.3 | 0.6% | Dec 2, 2025 | A vulnerability in Longwatch devices allows unauthenticated HTTP GET requests to execute arbitrary code via an exposed e... |
| CVE-2025-13542 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.... |
| CVE-2025-13510 | CRITICAL | 9.3 | 0.6% | Dec 2, 2025 | The Iskra iHUB and iHUB Lite smart metering gateway exposes its web management interface without requiring authenticatio... |
| CVE-2025-66409 | CRITICAL | 9.1 | 0.5% | Dec 2, 2025 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earli... |
| CVE-2025-65896 | CRITICAL | 9.8 | 0.4% | Dec 2, 2025 | SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via craf... |
| CVE-2025-60736 | CRITICAL | 9.8 | 0.4% | Dec 2, 2025 | code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter. |
| CVE-2025-60854 | CRITICAL | 9.8 | 1.0% | Dec 2, 2025 | A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during... |
| CVE-2025-58386 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper serv... |
| CVE-2025-65656 | CRITICAL | 9.8 | 0.4% | Dec 2, 2025 | dcat-admin v2.2.3-beta and before is vulnerable to file inclusion in admin/src/Extend/VersionManager.php. |
| CVE-2025-65358 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain SQl injection vulnerability via the 'docid' parameter at... |
| CVE-2025-13828 | CRITICAL | 9 | 0.2% | Dec 2, 2025 | SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even... |
| CVE-2025-59703 | CRITICAL | 9.1 | 0.4% | Dec 2, 2025 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (... |
| CVE-2025-59695 | CRITICAL | 9.8 | 0.6% | Dec 2, 2025 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (... |
| CVE-2025-59693 | CRITICAL | 9.8 | 0.7% | Dec 2, 2025 | The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patch... |
| CVE-2025-41013 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, cre... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now