2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13806 | CRITICAL | 9.8 | 0.5% | Dec 1, 2025 | A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of ... |
| CVE-2025-13800 | CRITICAL | 9.8 | 9.4% | Dec 1, 2025 | A vulnerability was found in ADSLR NBR1005GPEV2 250814-r037c. This issue affects the function set_mesh_disconnect of the... |
| CVE-2025-13799 | CRITICAL | 9.8 | 9.4% | Dec 1, 2025 | A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c. This vulnerability affects the function ap_macfilter_... |
| CVE-2025-13798 | CRITICAL | 9.8 | 6.3% | Dec 1, 2025 | A flaw has been found in ADSLR NBR1005GPEV2 250814-r037c. This affects the function ap_macfilter_add of the file /send_o... |
| CVE-2025-13797 | CRITICAL | 9.8 | 7.1% | Dec 1, 2025 | A vulnerability was detected in ADSLR B-QE2W401 250814-r037c. Affected by this issue is the function parameterdel_swifim... |
| CVE-2025-35028 | CRITICAL | 9.1 | 4.5% | Nov 30, 2025 | By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecu... |
| CVE-2025-13788 | CRITICAL | 9.8 | 0.4% | Nov 30, 2025 | A vulnerability has been found in Chanjet CRM up to 20251106. The impacted element is an unknown function of the file /t... |
| CVE-2025-13787 | CRITICAL | 9.1 | 0.4% | Nov 30, 2025 | A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/... |
| CVE-2025-13786 | CRITICAL | 9.8 | 0.6% | Nov 30, 2025 | A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fe... |
| CVE-2025-13783 | CRITICAL | 9.8 | 0.3% | Nov 30, 2025 | A security flaw has been discovered in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. This affects the fun... |
| CVE-2025-13782 | CRITICAL | 9.8 | 0.3% | Nov 30, 2025 | A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is... |
| CVE-2025-13615 | CRITICAL | 9.8 | 0.3% | Nov 30, 2025 | The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin... |
| CVE-2025-66216 | CRITICAL | 9.8 | 0.4% | Nov 29, 2025 | AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, a heap buffer overflow vulnerability has been ident... |
| CVE-2025-66219 | CRITICAL | 9.8 | 2.4% | Nov 29, 2025 | willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a comm... |
| CVE-2025-66034 | CRITICAL | 9.8 | 0.5% | Nov 29, 2025 | fontTools is a library for manipulating fonts, written in Python. In versions from 4.33.0 to before 4.60.2, the fonttool... |
| CVE-2025-65112 | CRITICAL | 9.8 | 0.5% | Nov 29, 2025 | PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubN... |
| CVE-2025-66385 | CRITICAL | 9.4 | 0.4% | Nov 28, 2025 | UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges ... |
| CVE-2025-12421 | CRITICAL | 9.9 | 0.3% | Nov 27, 2025 | Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that t... |
| CVE-2025-12419 | CRITICAL | 9.9 | 0.3% | Nov 27, 2025 | Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validat... |
| CVE-2025-8890 | CRITICAL | 9.3 | 0.9% | Nov 27, 2025 | Firmware in SDMC NE6037 routers prior to version 7.1.12.2.44 has a network diagnostics tool vulnerable to a shell comman... |
| CVE-2025-12140 | CRITICAL | 9.3 | 0.4% | Nov 27, 2025 | The application contains an insecure 'redirectToUrl' mechanism that incorrectly processes the value of the 'redirectUrlP... |
| CVE-2025-13675 | CRITICAL | 9.8 | 0.3% | Nov 27, 2025 | The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This ... |
| CVE-2025-13540 | CRITICAL | 9.8 | 0.3% | Nov 27, 2025 | The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.... |
| CVE-2025-13539 | CRITICAL | 9.8 | 0.4% | Nov 27, 2025 | The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,... |
| CVE-2025-13538 | CRITICAL | 9.8 | 0.3% | Nov 27, 2025 | The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now