2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2405 | HIGH | 7.6 | 0.3% | Dec 25, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Com... |
| CVE-2025-2307 | HIGH | 7.6 | 0.3% | Dec 25, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Com... |
| CVE-2025-66379 | HIGH | 7.5 | 0.3% | Dec 25, 2025 | Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trig... |
| CVE-2025-66378 | HIGH | 7.5 | 0.2% | Dec 25, 2025 | Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacke... |
| CVE-2025-66377 | HIGH | 7.5 | 0.2% | Dec 25, 2025 | Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an att... |
| CVE-2025-48704 | HIGH | 7.5 | 0.3% | Dec 25, 2025 | Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trig... |
| CVE-2025-32096 | HIGH | 7.5 | 0.3% | Dec 25, 2025 | Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigg... |
| CVE-2025-32095 | HIGH | 7.5 | 0.4% | Dec 25, 2025 | Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a softwa... |
| CVE-2025-15076 | HIGH | 7.3 | 0.6% | Dec 25, 2025 | A weakness has been identified in Tenda CH22 1.0.0.1. Impacted is an unknown function of the file /public/. Executing a ... |
| CVE-2025-68922 | HIGH | 7.4 | 0.2% | Dec 25, 2025 | OpenOps before 0.6.11 allows remote code execution in the Terraform block. |
| CVE-2025-68920 | HIGH | 8.9 | 0.4% | Dec 24, 2025 | C-Kermit (aka ckermit) through 10.0 Beta.12 (aka 416-beta12) before 244644d allows a remote Kermit system to overwrite f... |
| CVE-2025-68916 | HIGH | 7.2 | 2.3% | Dec 24, 2025 | Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload wi... |
| CVE-2025-3232 | HIGH | 8.7 | 0.5% | Dec 24, 2025 | A remote unauthenticated attacker may be able to bypass authentication by utilizing a specific API route to execute arb... |
| CVE-2025-2515 | HIGH | 7.2 | 0.2% | Dec 24, 2025 | A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS. This flaw allows a user wi... |
| CVE-2025-43876 | HIGH | 8.7 | 0.3% | Dec 24, 2025 | Under certain circumstances a successful exploitation could result in access to the device. |
| CVE-2025-43875 | HIGH | 8.7 | 0.3% | Dec 24, 2025 | Under certain circumstances a successful exploitation could result in access to the device. |
| CVE-2025-2155 | HIGH | 8.8 | 0.3% | Dec 24, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Spect... |
| CVE-2025-68748 | HIGH | 7.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix UAF race between device unplug and... |
| CVE-2025-68747 | HIGH | 7.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix UAF on kernel BO VA nodes If the ... |
| CVE-2025-68746 | HIGH | 7.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: spi: tegra210-quad: Fix timeout handling When the ... |
| CVE-2025-68736 | HIGH | 8.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: landlock: Fix handling of disconnected directories ... |
| CVE-2025-68735 | HIGH | 7.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Prevent potential UAF in group creatio... |
| CVE-2025-68608 | HIGH | 7.5 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in DeluxeThemes Userpro userpro allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2025-68590 | HIGH | 7.6 | 0.3% | Dec 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Integrat... |
| CVE-2025-68570 | HIGH | 7.6 | 0.3% | Dec 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Cap... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now