2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65865 | HIGH | 7.5 | 0.4% | Dec 23, 2025 | An integer overflow in eProsima Fast-DDS v3.3 allows attackers to cause a Denial of Service (DoS) via a crafted input. |
| CVE-2025-13183 | HIGH | 7.3 | 0.2% | Dec 23, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hotech Soft... |
| CVE-2025-68561 | HIGH | 7.6 | 0.2% | Dec 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia Autom... |
| CVE-2025-68560 | HIGH | 7.5 | 0.3% | Dec 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68550 | HIGH | 7.6 | 0.2% | Dec 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme WPBulky... |
| CVE-2025-68546 | HIGH | 7.5 | 0.3% | Dec 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68544 | HIGH | 7.5 | 0.3% | Dec 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-59886 | HIGH | 8.8 | 0.3% | Dec 23, 2025 | Improper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker w... |
| CVE-2025-12934 | HIGH | 8.1 | 0.4% | Dec 23, 2025 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to unauthorized access and modification o... |
| CVE-2025-68476 | HIGH | 8.2 | 0.4% | Dec 22, 2025 | KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Re... |
| CVE-2025-68475 | HIGH | 7.5 | 0.5% | Dec 22, 2025 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.6.13, 1.7.... |
| CVE-2025-65857 | HIGH | 7.5 | 0.4% | Dec 22, 2025 | An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetS... |
| CVE-2025-34458 | HIGH | 8.7 | 0.4% | Dec 22, 2025 | wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vul... |
| CVE-2025-34457 | HIGH | 8.7 | 0.5% | Dec 22, 2025 | wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 694c954, contain a stack-based buffer over... |
| CVE-2025-66736 | HIGH | 7.1 | 0.3% | Dec 22, 2025 | youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does n... |
| CVE-2025-66735 | HIGH | 7.5 | 0.4% | Dec 22, 2025 | youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does n... |
| CVE-2025-65817 | HIGH | 8.8 | 0.3% | Dec 22, 2025 | LSC Smart Connect Indoor IP Camera 1.4.13 contains a RCE vulnerability in start_app.sh. |
| CVE-2025-63664 | HIGH | 7.5 | 0.2% | Dec 22, 2025 | Incorrect access control in the /api/v1/conversations/*/messages API of GT Edge AI Platform before v2.0.10-dev allows un... |
| CVE-2025-63663 | HIGH | 7.5 | 0.2% | Dec 22, 2025 | Incorrect access control in the /api/v1/conversations/*/files API of GT Edge AI Platform before v2.0.10 allows unauthori... |
| CVE-2025-63662 | HIGH | 7.5 | 0.3% | Dec 22, 2025 | Insecure permissions in the /api/v1/agents API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers t... |
| CVE-2025-68645 | HIGH | 8.8 | 31.8% | Dec 22, 2025 | A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 ... |
| CVE-2025-68337 | HIGH | 7.5 | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: jbd2: avoid bug_on in jbd2_journal_get_create_acces... |
| CVE-2025-68336 | HIGH | 7.5 | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: locking/spinlock/debug: Fix data-race in do_raw_wri... |
| CVE-2025-10021 | HIGH | 7 | 0.1% | Dec 22, 2025 | A Use of Uninitialized Variable vulnerability exists in Open Design Alliance Drawings SDK static versions (mt) before 20... |
| CVE-2025-67826 | HIGH | 7.7 | 0.1% | Dec 22, 2025 | An issue was discovered in K7 Ultimate Security 17.0.2045. A Local Privilege Escalation (LPE) vulnerability in the K7 Ul... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now