2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68563 | HIGH | 7.5 | 0.3% | Dec 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68540 | HIGH | 7.5 | 0.3% | Dec 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68537 | HIGH | 7.5 | 0.3% | Dec 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68530 | HIGH | 7.5 | 0.3% | Dec 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68519 | HIGH | 8.5 | 0.2% | Dec 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BeRocket Brands fo... |
| CVE-2025-68506 | HIGH | 8.1 | 0.4% | Dec 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68496 | HIGH | 7.6 | 0.5% | Dec 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User F... |
| CVE-2025-68038 | HIGH | 7.2 | 0.4% | Dec 24, 2025 | Deserialization of Untrusted Data vulnerability in Icegram Icegram Express Pro email-subscribers-premium allows Object I... |
| CVE-2025-67909 | HIGH | 7.5 | 0.3% | Dec 24, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in WP Swings Membership For WooCommerce membership-for-wo... |
| CVE-2025-67622 | HIGH | 7.1 | 0.1% | Dec 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in titopandub Evergreen Post Tweeter evergreen-post-tweeter allows Store... |
| CVE-2025-68730 | HIGH | 7.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix page fault in ivpu_bo_unbind_all_bo... |
| CVE-2025-68724 | HIGH | 7.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: crypto: asymmetric_keys - prevent overflow in asymm... |
| CVE-2025-68379 | HIGH | 7.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix null deref on srq->rq.queue after res... |
| CVE-2025-68370 | HIGH | 7.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: coresight: tmc: add the handle of the event to the ... |
| CVE-2025-68369 | HIGH | 7.5 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: ntfs3: init run lock for extend inode After settin... |
| CVE-2025-68360 | HIGH | 8.2 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: wed: use proper wed reference in mt76 w... |
| CVE-2025-68352 | HIGH | 7.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: spi: ch341: fix out-of-bounds memory access in ch34... |
| CVE-2025-68349 | HIGH | 7.5 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark... |
| CVE-2025-68347 | HIGH | 7.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-motu: fix buffer overflow in hwdep r... |
| CVE-2025-66445 | HIGH | 7.1 | 0.2% | Dec 24, 2025 | Authorization bypass vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hit... |
| CVE-2025-66444 | HIGH | 8.2 | 0.2% | Dec 24, 2025 | Cross-site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hit... |
| CVE-2025-15053 | HIGH | 7.3 | 0.3% | Dec 24, 2025 | A flaw has been found in code-projects Student Information System 1.0. This issue affects some unknown processing of the... |
| CVE-2025-15050 | HIGH | 8.8 | 0.3% | Dec 24, 2025 | A security vulnerability has been detected in code-projects Student File Management System 1.0. This affects an unknown ... |
| CVE-2025-68696 | HIGH | 8.2 | 0.3% | Dec 23, 2025 | httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of lea... |
| CVE-2025-68664 | HIGH | 8.2 | 13.8% | Dec 23, 2025 | LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a seriali... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now