December 2025
5,771 CVEs published, +81% on November 2025 and +64% on December 2024. CISA added 20 to KEV.
2025 month by month
- Critical
- 3968% of the 4,785 with a CVSS score
- Added to CISA KEV
- 2019 of this month's CVEs are in KEV, listed a median 10 days after publication
- Vendors
- 2,1785,773 products
- Top weakness
- XSSCWE-79 · 826 CVEs
Who drove it
Vendors by distinct CVEs this month, with how many of those CVEs are now in CISA KEV and how far each moved in the ranking.
- 1LinuxLinux, Linux Kernel1,0551nonenew
- 2Сообщество Свободного Программного ОбеспеченияLinux, Debian Gnu/linux, Wpe Webkit450103new
- 3Red HatRed Hat Enterprise Linux, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 62111nonenew
- 4Ооо «русбитех-астра»Astra Linux Special Edition, Astra-safepolicy, Linux Astra Modules15171new
- 5CanonicalUbuntu, Apport, Maas1421nonenew
- 6AdobeAdobe Experience Manager, Experience Manager, Adobe Experience Manager Cloud Service1376nonenew
- 7GoogleAndroid, Chrome, Google Chrome13323new
- 8Ооо «ред Софт»Ред Ос, Ред База Данных8632new
- 9GoCode.gitea.io/gitea, Github.com/mattermost/mattermost/server/v8, Github.com/mattermost/mattermost8361new
- 10Ао «ивк»Альт Сп 10, Альт 8 Сп774nonenew
- 11npmN8N, @vitejs/plugin-rsc, React-server-dom-webpack7592new
- 12code-projectsStudent File Management System, Refugee Food Management System, Simple Stock System740nonenew
- 13PyPIPicklescan, Weblate, Mcp-server-git7481new
- 14MicrosoftWindows Server 2025, Windows 11 Version 24h2, Windows 11 Version 25h27232new
- 15ApplemacOS, iOS and iPadOS, Visionos6824new
- 16PackagistGetgrav/grav, Feehi/feehicms, Thorsten/phpmyfaq649nonenew
- 17Axiomthemes777, Agricola, Algenix580nonenew
- 18TendaWH450 Firmware, WH450, M35112nonenew
- 19Ао «сбертех»Platform V Sberlinux OS Server491nonenew
- 20AncorathemesChildhope, Chinchilla, Detailx481nonenew
- 21MavenOrg.jenkins-ci.main:jenkins-core, Org.nutz:nutzboot-parent, Org.apache.streampark:streampark482nonenew
- 22FabianStudent File Management System, Refugee Food Management System, Currency Exchange System460nonenew
- 23RuijieRg-eap602 Firmware, X30 Pro Firmware, Rg-ew300 Pro Firmware410nonenew
- 24ItsourcecodeStudent Management System, Online Cake Ordering System, Covid Tracking System390nonenew
- 25Mediatek, Inc.Mt2718, Mt6739, Mt6761, Mt6765, Mt6768, Mt6781, Mt6789, Mt6833, Mt6835, Mt6853, Mt6855, Mt6877, Mt6878, Mt6879, Mt6883, Mt6885, Mt6886, Mt6889, Mt6893, Mt6895, Mt6897, Mt6899, Mt6983, Mt6985, Mt6989, Mt6991, Mt8196, Mt8676, Mt8678, Mt8792, MT8793, Mt2735, Mt6833, Mt6833p, Mt6853, Mt6853t, Mt6855, Mt6855t, Mt6873, Mt6875, Mt6875t, Mt6877, Mt6877t, Mt6877tt, Mt6880, Mt6883, Mt6885, Mt6889, Mt6890, Mt6891, Mt6893, Mt8675, Mt8771, Mt8791, Mt8791t, MT8797, Mt6739, Mt6761, Mt6765, Mt6768, Mt6781, Mt6789, Mt6833, Mt6835, Mt6853, Mt6855, Mt6877, Mt6878, Mt6879, Mt6883, Mt6885, Mt6886, Mt6889, Mt6893, Mt6895, Mt6897, Mt6899, Mt6983, Mt6985, Mt6989, Mt6991, Mt8186, Mt8188, Mt8196, Mt8667, Mt8673, Mt8676, Mt8678, Mt8765, Mt8766, Mt8768, Mt8771, Mt8781, Mt8791t, Mt8792, Mt8793, Mt8795t, Mt8796, Mt8798, Mt8873, MT8883300nonenew
Severity
How this month's CVEs score on CVSS; 986 have no score yet. Severity is not exploitation.
- Critical396
- High1,715
- Medium2,480
- Low194
New in the top 100
Not in the top 100 in any of the 24 months before.
What kind of weakness
Weakness classes (CWE) by distinct CVEs, with how far each moved in the ranking.
- CWE-79XSS826
- CWE-862Missing Authorization418
- CWE-89SQL Injection285
- CWE-74Injection209
- CWE-352CSRF191
- CWE-98169
- CWE-22Path Traversal143
- CWE-94Code Injection141
- CWE-78OS Command Injection118
- CWE-284Improper Access Control103
- CWE-787Out-of-bounds Write102
- CWE-434Unrestricted File Upload101
- CWE-502Deserialization96
- CWE-119Memory Buffer Bounds94
- CWE-20Improper Input Validation93
- CWE-77Command Injection85
- CWE-12179
- CWE-200Information Exposure78
- CWE-306Missing Auth for Critical Function78
- CWE-639Auth Bypass via User Key75
Where it landed
The month's CVEs by the sector of the software they affect. A CVE that touches several sectors counts in each.
- Web & CMS Plugins1,42322% of sector-tagged CVEs
- Operating Systems1,37921% of sector-tagged CVEs
- OSS Libraries5509% of sector-tagged CVEs
- Enterprise Software5128% of sector-tagged CVEs
- Consumer Software3465% of sector-tagged CVEs
- ICS / OT / IoT3105% of sector-tagged CVEs
- Networking Infrastructure2784% of sector-tagged CVEs
- Mobile Apps2444% of sector-tagged CVEs
- 7 smaller sectors931
- Not yet classified449
Which weakness, where
The top weakness classes against the vendors and the sectors that carried them.
The lighter the cell, the more CVEs. Point at one to read it.
| By vendor | 79XSS | 862Missing Authorization | 89SQL Injection | 74Injection | 352CSRF | 98 | 22Path Traversal | 94Code Injection | 78OS Command Injection | 284Improper Access Control |
|---|---|---|---|---|---|---|---|---|---|---|
| Linux | ||||||||||
| Сообщество Свободного Программного Обеспечения | 2 | 1 | 1 | 1 | 1 | |||||
| Red Hat Inc. | 1 | 1 | 1 | |||||||
| Ооо «русбитех-астра» | 1 | 1 | 3 | 1 | 1 | |||||
| Canonical Ltd. | 1 | |||||||||
| Adobe Systems Inc. | 116 | 1 | 1 | |||||||
| Adobe | 115 | 1 | 1 | |||||||
| 1 | 8 | 1 | ||||||||
| Ооо «ред Софт» | 6 | 2 | 1 | 1 | 1 | 1 | 2 | 1 | ||
| Ао «ивк» | 1 | 1 | ||||||||
| Go | 5 | 4 | 7 | 1 | 4 | |||||
| npm | 9 | 1 | 2 | 4 | 2 |
In the news
The CVEs security news mentioned most in December 2025.
- CVE-2025-13659Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, pot...18.8
- CVE-2025-34392Barracuda RMM < 2025.1.1 Service Center Absolute Path Traversal RCE19.8
- CVE-2025-50165Windows Graphics Component Remote Code Execution Vulnerability19.8
- CVE-2025-64374WordPress Motors theme <= 5.6.81 - Arbitrary File Upload vulnerability19.9