2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62001 | HIGH | 8.8 | 0.3% | Dec 18, 2025 | BullWall Ransomware Containment supports configurable file and directory exclusions such as '$RECYCLE.BIN' to balance mo... |
| CVE-2025-62000 | HIGH | 7.1 | 0.2% | Dec 18, 2025 | BullWall Ransomware Containment may not always detect an encrypted file. This issue affects a specific file inspection m... |
| CVE-2025-53710 | HIGH | 7.5 | 0.2% | Dec 18, 2025 | Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace... |
| CVE-2025-46268 | HIGH | 8.8 | 0.3% | Dec 18, 2025 | Advantech WebAccess/SCADA is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands... |
| CVE-2025-13911 | HIGH | 7.3 | 0.2% | Dec 18, 2025 | The vulnerability affects Ignition SCADA applications where Python scripting is utilized for automation purposes. The v... |
| CVE-2025-65566 | HIGH | 7.5 | 0.3% | Dec 18, 2025 | A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.... |
| CVE-2025-67745 | HIGH | 7.5 | 0.1% | Dec 18, 2025 | MyHoard is a daemon for creating, managing and restoring MySQL backups. Starting in version 1.0.1 and prior to version 1... |
| CVE-2025-65568 | HIGH | 7.5 | 0.4% | Dec 18, 2025 | A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.... |
| CVE-2025-65567 | HIGH | 7.5 | 0.3% | Dec 18, 2025 | A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.... |
| CVE-2025-65565 | HIGH | 7.5 | 0.3% | Dec 18, 2025 | A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.... |
| CVE-2025-65564 | HIGH | 7.5 | 0.4% | Dec 18, 2025 | A denial-of-service vulnerability exists in the omec-upf (upf-epc-pfcpiface) in version upf-epc-pfcpiface:2.1.3-dev. Whe... |
| CVE-2025-65563 | HIGH | 7.5 | 0.4% | Dec 18, 2025 | A denial-of-service vulnerability exists in the omec-project UPF (component upf-epc/pfcpiface) up to at least version up... |
| CVE-2025-65562 | HIGH | 7.5 | 0.5% | Dec 18, 2025 | The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An un... |
| CVE-2025-65561 | HIGH | 7.5 | 0.4% | Dec 18, 2025 | An issue was discovered in function LocalNode.Sess in free5GC 4.1.0 allowing attackers to cause a denial of service or o... |
| CVE-2025-65559 | HIGH | 7.5 | 0.4% | Dec 18, 2025 | An issue was discovered in Open5GS 2.7.5-49-g465e90f, when processing a PFCP Session Establishment Request (type=50), th... |
| CVE-2025-63387 | HIGH | 7.5 | 28.0% | Dec 18, 2025 | Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to th... |
| CVE-2025-14885 | HIGH | 8.8 | 0.3% | Dec 18, 2025 | A flaw has been found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file ... |
| CVE-2025-14738 | HIGH | 7.5 | 0.4% | Dec 18, 2025 | Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download th... |
| CVE-2025-14737 | HIGH | 8 | 1.0% | Dec 18, 2025 | Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to inject arbi... |
| CVE-2025-14896 | HIGH | 8.7 | 0.3% | Dec 18, 2025 | due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an a... |
| CVE-2025-14884 | HIGH | 7.3 | 9.4% | Dec 18, 2025 | A vulnerability was detected in D-Link DIR-605 202WWB03. Affected by this issue is some unknown functionality of the com... |
| CVE-2025-68278 | HIGH | 8.8 | 0.4% | Dec 18, 2025 | Tina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in... |
| CVE-2025-64724 | HIGH | 7.3 | 0.1% | Dec 18, 2025 | Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with wo... |
| CVE-2025-65011 | HIGH | 7.1 | 0.2% | Dec 18, 2025 | In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) an unauthorised user can view configuration files by d... |
| CVE-2025-65010 | HIGH | 7.1 | 0.2% | Dec 18, 2025 | WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) is vulnerable to Broken Access Control in initial configu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now