2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13053 | LOW | 3.7 | 0.1% | Dec 12, 2025 | When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification ca... |
| CVE-2025-14538 | LOW | 3.5 | 0.2% | Dec 11, 2025 | A security vulnerability has been detected in yangshare warehouseManager 仓库管理系统 1.1.0. This affects the function addCust... |
| CVE-2025-13912 | LOW | 1 | 0.1% | Dec 11, 2025 | Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary ... |
| CVE-2025-67739 | LOW | 3.1 | 0.1% | Dec 11, 2025 | In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure |
| CVE-2025-55307 | LOW | 3.3 | 0.1% | Dec 11, 2025 | An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. Opening a malicious PDF ... |
| CVE-2025-12734 | LOW | 3.5 | 0.2% | Dec 11, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 1... |
| CVE-2025-67646 | LOW | 3.5 | 0.1% | Dec 11, 2025 | TableProgressTracking is a MediaWiki extension to track progress against specific criterion. Versions 1.2.0 and below do... |
| CVE-2025-5467 | LOW | 3.3 | 0.1% | Dec 10, 2025 | It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files ... |
| CVE-2025-67639 | LOW | 3.5 | 0.2% | Dec 10, 2025 | A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers... |
| CVE-2025-13127 | LOW | 3.5 | 0.2% | Dec 10, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TAC Informa... |
| CVE-2025-14082 | LOW | 2.7 | 0.3% | Dec 10, 2025 | A flaw was found in Keycloak Admin REST (Representational State Transfer) API. This vulnerability allows information dis... |
| CVE-2025-67500 | LOW | 3.7 | 0.2% | Dec 10, 2025 | Mastodon is a free, open-source social network server based on ActivityPub. Versions 4.2.27 and prior, 4.3.0-beta.1 thro... |
| CVE-2025-67499 | LOW | 3.6 | 0.1% | Dec 10, 2025 | The CNI portmap plugin allows containers to emulate opening a host port, forwarding that traffic to the container. Versi... |
| CVE-2025-64787 | LOW | 3.3 | 0.4% | Dec 9, 2025 | Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by... |
| CVE-2025-64786 | LOW | 3.3 | 0.4% | Dec 9, 2025 | Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by... |
| CVE-2025-59923 | LOW | 2.7 | 0.2% | Dec 9, 2025 | An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all ... |
| CVE-2025-57823 | LOW | 2.7 | 0.2% | Dec 9, 2025 | A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticato... |
| CVE-2025-64255 | LOW | 2.7 | 0.3% | Dec 9, 2025 | Missing Authorization vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Exploiting ... |
| CVE-2025-64254 | LOW | 2.7 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in Ronald Huereca Photo Block photo-block allows Exploiting Incorrectly Configured A... |
| CVE-2025-40818 | LOW | 3.3 | 0.1% | Dec 9, 2025 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications con... |
| CVE-2025-36102 | LOW | 2.7 | 0.2% | Dec 8, 2025 | IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow a privileged user t... |
| CVE-2025-65228 | LOW | 3.5 | 0.2% | Dec 8, 2025 | A stored cross-site scripting vulnerability exists in the web management interface of the R.V.R. Elettronica TLK302T tel... |
| CVE-2025-60912 | LOW | 3.3 | 0.2% | Dec 8, 2025 | phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The gene... |
| CVE-2025-14228 | LOW | 3.5 | 0.2% | Dec 8, 2025 | A weakness has been identified in Yealink SIP-T21P E2 52.84.0.15. Impacted is an unknown function of the component Local... |
| CVE-2025-14186 | LOW | 3.5 | 0.2% | Dec 7, 2025 | A security flaw has been discovered in Grandstream GXP1625 1.0.7.4. The impacted element is an unknown function of the f... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now