2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14300 | HIGH | 8.1 | 0.3% | Dec 20, 2025 | The HTTPS service on Tapo C200 V3 exposes a connectAP interface without proper authentication. An unauthenticated attack... |
| CVE-2025-68613 | HIGH | 8.8 | 97.9% | Dec 19, 2025 | n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.... |
| CVE-2025-68481 | HIGH | 8.8 | 0.2% | Dec 19, 2025 | FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to ve... |
| CVE-2025-14966 | HIGH | 7.2 | 0.3% | Dec 19, 2025 | A vulnerability was determined in FastAdmin up to 1.7.0.20250506. Affected is the function selectpage of the file applic... |
| CVE-2025-68478 | HIGH | 7.1 | 3.6% | Dec 19, 2025 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary p... |
| CVE-2025-14958 | HIGH | 7.8 | 0.2% | Dec 19, 2025 | A security flaw has been discovered in floooh sokol up to 33e2271c431bf21de001e972f72da17a984da932. This vulnerability a... |
| CVE-2025-58052 | HIGH | 8.1 | 0.3% | Dec 19, 2025 | Galette is a membership management web application for non profit organizations. Starting in version 0.9.6 and prior to ... |
| CVE-2025-14956 | HIGH | 7.1 | 0.2% | Dec 19, 2025 | A vulnerability was determined in WebAssembly Binaryen up to 125. Affected by this issue is the function WasmBinaryReade... |
| CVE-2025-14812 | HIGH | 7.5 | 0.2% | Dec 19, 2025 | ArcSearch for iOS versions prior to 1.45.2 could display a different domain in the address bar than the content being sh... |
| CVE-2025-14809 | HIGH | 7.4 | 0.2% | Dec 19, 2025 | ArcSearch for Android versions prior to 1.12.6 could display a different domain in the address bar than the content bein... |
| CVE-2025-67442 | HIGH | 7.6 | 0.5% | Dec 19, 2025 | EVE-NG 6.4.0-13-PRO is vulnerable to Directory Traversal. The /api/export interface allows authenticated users to export... |
| CVE-2025-66905 | HIGH | 7.5 | 0.5% | Dec 19, 2025 | The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them ... |
| CVE-2025-66909 | HIGH | 7.5 | 0.5% | Dec 19, 2025 | Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an image decompression bomb denial of service vulnerabilit... |
| CVE-2025-50681 | HIGH | 7.5 | 0.4% | Dec 19, 2025 | igmpproxy 0.4 before commit 2b30c36 allows remote attackers to cause a denial of service (application crash) via a craft... |
| CVE-2025-1927 | HIGH | 7.1 | 0.1% | Dec 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Restajet Information Technologies Inc. Online Food Delivery System al... |
| CVE-2025-14847 | HIGH | 8.7 | 83.0% | Dec 19, 2025 | Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthe... |
| CVE-2025-66524 | HIGH | 8.8 | 0.4% | Dec 19, 2025 | Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Di... |
| CVE-2025-14151 | HIGH | 7.2 | 0.4% | Dec 19, 2025 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'outbound_resource' par... |
| CVE-2025-66499 | HIGH | 7.8 | 0.3% | Dec 19, 2025 | A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially craft... |
| CVE-2025-66498 | HIGH | 7.8 | 0.2% | Dec 19, 2025 | A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds ch... |
| CVE-2025-66497 | HIGH | 7.8 | 0.2% | Dec 19, 2025 | A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds ch... |
| CVE-2025-66496 | HIGH | 7.8 | 0.2% | Dec 19, 2025 | A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds ch... |
| CVE-2025-66495 | HIGH | 7.8 | 0.3% | Dec 19, 2025 | A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1... |
| CVE-2025-66494 | HIGH | 7.8 | 0.3% | Dec 19, 2025 | A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on... |
| CVE-2025-66493 | HIGH | 7.8 | 0.3% | Dec 19, 2025 | A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now