2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36228 | LOW | 3.8 | 0.2% | Dec 26, 2025 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API... |
| CVE-2025-52598 | LOW | 3.7 | 0.2% | Dec 26, 2025 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io... |
| CVE-2025-15095 | LOW | 3.5 | 0.3% | Dec 26, 2025 | A security vulnerability has been detected in postmanlabs httpbin up to 0.6.1. This affects an unknown function of the f... |
| CVE-2025-15084 | LOW | 3.1 | 0.2% | Dec 25, 2025 | A vulnerability was identified in youlaitech youlai-mall 1.0.0/2.0.0. The impacted element is the function orderService.... |
| CVE-2025-68585 | LOW | 2.7 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Ben Balter WP Document Revisions wp-document-revisions allows Exploiting Incorrec... |
| CVE-2025-57840 | LOW | 2.2 | 0.1% | Dec 24, 2025 | ADB(Android Debug Bridge) is affected by type privilege bypass, successful exploitation of this vulnerability may affect... |
| CVE-2025-14408 | LOW | 3.3 | 0.1% | Dec 23, 2025 | Soda PDF Desktop PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows rem... |
| CVE-2025-61738 | LOW | 2.3 | 0.2% | Dec 22, 2025 | Under certain circumstances, attacker can capture the network key, read or write encrypted packets on the PowerG network... |
| CVE-2025-15005 | LOW | 3.7 | 0.4% | Dec 22, 2025 | A security flaw has been discovered in CouchCMS up to 2.4. Affected is an unknown function of the file couch/config.exam... |
| CVE-2025-12654 | LOW | 2.7 | 0.4% | Dec 21, 2025 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory cr... |
| CVE-2025-14955 | LOW | 3.7 | 0.5% | Dec 19, 2025 | A vulnerability was found in Open5GS up to 2.7.5. Affected by this vulnerability is the function ogs_pfcp_handle_create_... |
| CVE-2025-14882 | LOW | 3.8 | 0.2% | Dec 19, 2025 | An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intende... |
| CVE-2025-14881 | LOW | 3.8 | 0.2% | Dec 19, 2025 | Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not ... |
| CVE-2025-65046 | LOW | 3.1 | 0.2% | Dec 18, 2025 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2025-68469 | LOW | 3.3 | 0.2% | Dec 18, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14... |
| CVE-2025-68462 | LOW | 3.2 | 0.1% | Dec 18, 2025 | Freedombox before 25.17.1 does not set proper permissions for the backups-data directory, allowing the reading of dump f... |
| CVE-2025-14841 | LOW | 3.3 | 0.1% | Dec 18, 2025 | A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted element is the function DcmQueryRetrieveIndexDatabaseHand... |
| CVE-2025-14836 | LOW | 2.7 | 0.2% | Dec 17, 2025 | A flaw has been found in ZZCMS 2025. Affected by this vulnerability is an unknown functionality of the file /reg/user_sa... |
| CVE-2025-46279 | LOW | 3.3 | 0.3% | Dec 17, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS... |
| CVE-2025-46277 | LOW | 3.3 | 0.2% | Dec 17, 2025 | A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe... |
| CVE-2025-43531 | LOW | 3.1 | 0.4% | Dec 17, 2025 | A race condition was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 1... |
| CVE-2025-13326 | LOW | 3.9 | 0.1% | Dec 17, 2025 | Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged f... |
| CVE-2025-13324 | LOW | 3.7 | 0.2% | Dec 17, 2025 | Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite to... |
| CVE-2025-13321 | LOW | 3.3 | 0.1% | Dec 17, 2025 | Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on ser... |
| CVE-2025-65185 | LOW | 2.8 | 0.1% | Dec 17, 2025 | There is a username enumeration via local user login in Entrinsik Informer v5.10.1 which allows malicious users to enume... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now