2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14266 | LOW | 0.6 | 0.2% | Dec 17, 2025 | CSRF in Ercom Cryptobox administration console allows attacker to trigger some actions on behalf of a Cryptobox administ... |
| CVE-2025-13352 | LOW | 3 | 0.1% | Dec 17, 2025 | Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identit... |
| CVE-2025-68164 | LOW | 2.7 | 0.2% | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test |
| CVE-2025-68162 | LOW | 2.7 | 0.2% | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration |
| CVE-2025-54004 | LOW | 2.7 | 0.3% | Dec 16, 2025 | Missing Authorization vulnerability in WC Lovers WCFM – Frontend Manager for WooCommerce wc-frontend-manager allows Expl... |
| CVE-2025-49300 | LOW | 2.7 | 0.2% | Dec 16, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in shinetheme Traveler Option Tree custom-option-tree al... |
| CVE-2025-14722 | LOW | 2.4 | 0.2% | Dec 15, 2025 | A vulnerability was determined in vion707 DMadmin up to 3403cafdb42537a648c30bf8cbc8148ec60437d1. This impacts the funct... |
| CVE-2025-55703 | LOW | 3.3 | 0.1% | Dec 15, 2025 | An error-based SQL injection vulnerability exists in the Sunbird Power IQ 9.2.0 API. The vulnerability is due to an outd... |
| CVE-2025-14697 | LOW | 3.7 | 0.3% | Dec 15, 2025 | A security flaw has been discovered in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3... |
| CVE-2025-67899 | LOW | 2.9 | 0.1% | Dec 14, 2025 | uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with... |
| CVE-2025-14651 | LOW | 3.7 | 0.3% | Dec 14, 2025 | A vulnerability has been found in MartialBE one-hub up to 0.14.27. This vulnerability affects unknown code of the file d... |
| CVE-2025-14636 | LOW | 3.7 | 0.2% | Dec 13, 2025 | A security flaw has been discovered in Tenda AX9 22.03.01.46. This affects the function image_check of the component htt... |
| CVE-2025-9218 | LOW | 3.7 | 0.2% | Dec 13, 2025 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to... |
| CVE-2025-43532 | LOW | 2.8 | 0.3% | Dec 12, 2025 | A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.3 and iPadOS 18.7... |
| CVE-2025-43522 | LOW | 3.3 | 0.1% | Dec 12, 2025 | A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issu... |
| CVE-2025-43518 | LOW | 3.3 | 0.1% | Dec 12, 2025 | A logic issue was addressed with improved checks. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3,... |
| CVE-2025-43517 | LOW | 3.3 | 0.2% | Dec 12, 2025 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia... |
| CVE-2025-43516 | LOW | 3.3 | 0.1% | Dec 12, 2025 | A session management issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma... |
| CVE-2025-43437 | LOW | 3.3 | 0.1% | Dec 12, 2025 | An information disclosure issue was addressed with improved privacy controls. This issue is fixed in iOS 26.1 and iPadOS... |
| CVE-2025-43410 | LOW | 2.4 | 0.2% | Dec 12, 2025 | The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8... |
| CVE-2025-43404 | LOW | 3.3 | 0.1% | Dec 12, 2025 | A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. An app ... |
| CVE-2025-36755 | LOW | 2.4 | 0.1% | Dec 12, 2025 | The CleverDisplay BlueOne hardware player is designed with its USB interfaces physically enclosed and inaccessible under... |
| CVE-2025-36744 | LOW | 2.4 | 0.1% | Dec 12, 2025 | SolarEdge SE3680H has unauthenticated disclosure of sensitive information during the bootloader loop. While the device r... |
| CVE-2025-10583 | LOW | 3.5 | 0.2% | Dec 12, 2025 | The WP Fastest Cache Premium plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an... |
| CVE-2025-67737 | LOW | 3.7 | 0.2% | Dec 12, 2025 | AzuraCast is a self-hosted, all-in-one web radio management suite. Versions 0.23.1 mistakenly include an API endpoint th... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now