2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15107 | HIGH | 8.1 | 0.6% | Dec 27, 2025 | A security vulnerability has been detected in actiontech sqle up to 4.2511.0. The impacted element is an unknown functio... |
| CVE-2025-68948 | HIGH | 8.1 | 0.2% | Dec 27, 2025 | SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note ... |
| CVE-2025-59946 | HIGH | 7.5 | 0.3% | Dec 27, 2025 | NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing iss... |
| CVE-2025-68474 | HIGH | 7.6 | 0.3% | Dec 27, 2025 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, ... |
| CVE-2025-68473 | HIGH | 8.6 | 0.4% | Dec 27, 2025 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, ... |
| CVE-2025-68148 | HIGH | 7.5 | 0.4% | Dec 27, 2025 | FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny ... |
| CVE-2025-67729 | HIGH | 8.8 | 0.5% | Dec 26, 2025 | LMDeploy is a toolkit for compressing, deploying, and serving LLMs. Prior to version 0.11.1, an insecure deserialization... |
| CVE-2025-67015 | HIGH | 7.5 | 0.4% | Dec 26, 2025 | Incorrect access control in Comtech EF Data CDM-625 / CDM-625A Advanced Satellite Modem with firmware v2.5.1 allows atta... |
| CVE-2025-67014 | HIGH | 7.5 | 0.5% | Dec 26, 2025 | Incorrect access control in DEV Systemtechnik GmbH DEV 7113 RF over Fiber Distribution System 32-0078 H.01 allows unauth... |
| CVE-2025-66738 | HIGH | 8.8 | 0.6% | Dec 26, 2025 | An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a ... |
| CVE-2025-57403 | HIGH | 7.5 | 1.0% | Dec 26, 2025 | Cola Dnslog v1.3.2 is vulnerable to Directory Traversal. When a DNS query for a TXT record is processed, the application... |
| CVE-2025-64645 | HIGH | 7.4 | 0.1% | Dec 26, 2025 | IBM Concert 1.0.0 through 2.1.0 could allow a local user to escalate their privileges due to a race condition of a symbo... |
| CVE-2025-25341 | HIGH | 7.5 | 0.4% | Dec 26, 2025 | A vulnerability exists in the libxmljs 1.0.11 when parsing a specially crafted XML document. Accessing the internal _ref... |
| CVE-2025-36192 | HIGH | 7.1 | 0.1% | Dec 26, 2025 | IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM DS8900F ( R9.4) 89.40.83.089.42.18.089.... |
| CVE-2025-1721 | HIGH | 7.5 | 0.3% | Dec 26, 2025 | IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due ... |
| CVE-2025-12771 | HIGH | 7.8 | 0.1% | Dec 26, 2025 | IBM Concert 1.0.0 through 2.1.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A lo... |
| CVE-2025-67450 | HIGH | 7.8 | 0.1% | Dec 26, 2025 | Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software ... |
| CVE-2025-59887 | HIGH | 8.6 | 0.3% | Dec 26, 2025 | Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code exec... |
| CVE-2025-62578 | HIGH | 7.5 | 0.4% | Dec 26, 2025 | DVP-12SE - Modbus/TCP Cleartext Transmission of Sensitive Information |
| CVE-2025-52601 | HIGH | 7.8 | 0.1% | Dec 26, 2025 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io... |
| CVE-2025-52600 | HIGH | 7.2 | 0.4% | Dec 26, 2025 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io... |
| CVE-2025-15097 | HIGH | 7.3 | 0.5% | Dec 26, 2025 | A vulnerability was found in Alteryx Server. Affected by this issue is some unknown functionality of the file /gallery/a... |
| CVE-2025-15085 | HIGH | 8.1 | 0.3% | Dec 25, 2025 | A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of th... |
| CVE-2025-15082 | HIGH | 7.5 | 0.6% | Dec 25, 2025 | A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/proc_post o... |
| CVE-2025-2406 | HIGH | 7.6 | 0.3% | Dec 25, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Com... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now