2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61740 | HIGH | 7.2 | 0.1% | Dec 22, 2025 | Authentication issue that does not verify the source of a packet which could allow an attacker to create a denial-of-ser... |
| CVE-2025-26379 | HIGH | 7.2 | 0.2% | Dec 22, 2025 | Use of a weak pseudo-random number generator, which may allow an attacker to read or inject encrypted PowerG packets. |
| CVE-2025-14018 | HIGH | 7.3 | 0.4% | Dec 22, 2025 | Unquoted Search Path or Element vulnerability in NetBT Consulting Services Inc. E-Fatura allows Leveraging/Manipulating ... |
| CVE-2025-14273 | HIGH | 8.3 | 0.2% | Dec 22, 2025 | Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enab... |
| CVE-2025-61739 | HIGH | 7.2 | 0.2% | Dec 22, 2025 | Due to Nonce reuse, attackers can perform reply attack or decrypt captured packets. |
| CVE-2025-12514 | HIGH | 7.2 | 0.3% | Dec 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Mon... |
| CVE-2025-11540 | HIGH | 7.5 | 0.3% | Dec 22, 2025 | Path Traversal vulnerability in Sharp Display Solutions projectors allows a attacker may access and read any files withi... |
| CVE-2025-59301 | HIGH | 7.5 | 0.2% | Dec 22, 2025 | Delta Electronics DVP15MC11T lacks proper validation of the modbus/tcp packets and can lead to denial of service. |
| CVE-2025-15015 | HIGH | 8.7 | 0.5% | Dec 22, 2025 | Enterprise Cloud Database developed by Ragic has a Arbitrary File Read vulnerability, allowing unauthenticated remote at... |
| CVE-2025-15009 | HIGH | 8.8 | 0.3% | Dec 22, 2025 | A flaw has been found in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function FilenameUtils.getExten... |
| CVE-2025-15004 | HIGH | 8.8 | 0.3% | Dec 22, 2025 | A vulnerability was identified in DedeCMS up to 5.7.118. This impacts an unknown function of the file /freelist_main.php... |
| CVE-2025-15003 | HIGH | 7.2 | 0.3% | Dec 22, 2025 | A vulnerability was found in SeaCMS up to 13.3. The impacted element is an unknown function of the file admin_video.php.... |
| CVE-2025-14995 | HIGH | 8.8 | 0.6% | Dec 21, 2025 | A vulnerability has been found in Tenda FH1201 1.2.0.14(408). Affected is the function sprintf of the file /goform/SetIp... |
| CVE-2025-14994 | HIGH | 8.8 | 0.6% | Dec 21, 2025 | A flaw has been found in Tenda FH1201 and FH1206 1.2.0.14(408)/1.2.0.8(8155). This impacts the function strcat of the fi... |
| CVE-2025-14855 | HIGH | 7.2 | 0.3% | Dec 21, 2025 | The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all ver... |
| CVE-2025-14800 | HIGH | 8.1 | 0.3% | Dec 21, 2025 | The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type... |
| CVE-2025-14993 | HIGH | 8.8 | 0.7% | Dec 21, 2025 | A vulnerability was detected in Tenda AC18 15.03.05.05. This affects the function sprintf of the file /goform/SetDlnaCfg... |
| CVE-2025-9343 | HIGH | 7.2 | 0.2% | Dec 21, 2025 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2025-68644 | HIGH | 7.4 | 0.3% | Dec 21, 2025 | Yealink RPS before 2025-06-27 allows unauthorized access to information, including AutoP URL addresses. This was fixed b... |
| CVE-2025-14992 | HIGH | 8.8 | 0.6% | Dec 21, 2025 | A security vulnerability has been detected in Tenda AC18 15.03.05.05. The impacted element is the function strcpy of the... |
| CVE-2025-14071 | HIGH | 7.5 | 0.6% | Dec 21, 2025 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all ver... |
| CVE-2025-12980 | HIGH | 7.5 | 0.3% | Dec 21, 2025 | The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthor... |
| CVE-2025-34290 | HIGH | 8.5 | 0.1% | Dec 20, 2025 | Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerabili... |
| CVE-2025-7782 | HIGH | 7.6 | 0.2% | Dec 20, 2025 | The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to unauthorized modification of data due... |
| CVE-2025-14591 | HIGH | 7.5 | 0.2% | Dec 20, 2025 | In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windo... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now