2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14965 | MEDIUM | 5.5 | 0.3% | Dec 19, 2025 | A vulnerability was found in 1541492390c yougou-mall up to 0a771fa817c924efe52c8fe0a9a6658eee675f9f. This impacts the fu... |
| CVE-2025-14962 | MEDIUM | 6.1 | 0.3% | Dec 19, 2025 | A flaw has been found in code-projects Simple Stock System 1.0. The impacted element is an unknown function of the file ... |
| CVE-2025-68430 | MEDIUM | 4.3 | 0.2% | Dec 19, 2025 | CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.8.1 through 2.52.0... |
| CVE-2025-68477 | MEDIUM | 6.5 | 5.8% | Dec 19, 2025 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, Langflow provides... |
| CVE-2025-68457 | MEDIUM | 6.1 | 0.2% | Dec 19, 2025 | Orejime is a consent manager that focuses on accessibility. On HTML elements handled by Orejime prior to version 2.3.2, ... |
| CVE-2025-65035 | MEDIUM | 6.4 | 0.3% | Dec 19, 2025 | pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the d... |
| CVE-2025-14957 | MEDIUM | 5.5 | 0.2% | Dec 19, 2025 | A vulnerability was identified in WebAssembly Binaryen up to 125. This affects the function IRBuilder::makeLocalGet/IRBu... |
| CVE-2025-66906 | MEDIUM | 6.1 | 0.1% | Dec 19, 2025 | Cross Site Request Forgery (CSRF) vulnerability in Turms Admin API thru v0.10.0-SNAPSHOT allows attackers to gain escala... |
| CVE-2025-53922 | MEDIUM | 4.9 | 0.2% | Dec 19, 2025 | Galette is a membership management web application for non profit organizations. Starting in version 1.1.4 and prior to ... |
| CVE-2025-14954 | MEDIUM | 5.9 | 0.5% | Dec 19, 2025 | A vulnerability has been found in Open5GS up to 2.7.6. Affected is the function ogs_pfcp_pdr_find_or_add/ogs_pfcp_far_fi... |
| CVE-2025-14953 | MEDIUM | 5.3 | 0.4% | Dec 19, 2025 | A flaw has been found in Open5GS up to 2.7.5. This impacts the function ogs_pfcp_handle_create_pdr in the library lib/pf... |
| CVE-2025-66911 | MEDIUM | 6.5 | 0.3% | Dec 19, 2025 | Turms IM Server v0.10.0-SNAPSHOT and earlier contains a broken access control vulnerability in the user online status qu... |
| CVE-2025-66910 | MEDIUM | 6 | 0.2% | Dec 19, 2025 | Turms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authe... |
| CVE-2025-66908 | MEDIUM | 5.3 | 0.4% | Dec 19, 2025 | Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an improper file type validation vulnerability in the OCR ... |
| CVE-2025-14946 | MEDIUM | 4.8 | 0.1% | Dec 19, 2025 | A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Unifor... |
| CVE-2025-1885 | MEDIUM | 5.4 | 0.1% | Dec 19, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Restajet Information Technologies Inc. Online Food ... |
| CVE-2025-14455 | MEDIUM | 5.4 | 0.3% | Dec 19, 2025 | The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to authorization bypass in all versions up t... |
| CVE-2025-12361 | MEDIUM | 4.3 | 0.2% | Dec 19, 2025 | The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vulne... |
| CVE-2025-11747 | MEDIUM | 6.4 | 0.3% | Dec 19, 2025 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the colibri_blog_posts sh... |
| CVE-2025-66522 | MEDIUM | 5.4 | 0.1% | Dec 19, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the Digital IDs functionality of the Foxit PDF Editor Cloud ... |
| CVE-2025-66521 | MEDIUM | 5.4 | 0.1% | Dec 19, 2025 | A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Trusted Certificates feature.... |
| CVE-2025-66520 | MEDIUM | 5.4 | 0.1% | Dec 19, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the Portfolio feature of the Foxit PDF Editor cloud (pdfonli... |
| CVE-2025-66519 | MEDIUM | 5.4 | 0.1% | Dec 19, 2025 | A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Layer Import functionality. A... |
| CVE-2025-66502 | MEDIUM | 5.4 | 0.1% | Dec 19, 2025 | A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Page Templates feature. A cra... |
| CVE-2025-66501 | MEDIUM | 5.4 | 0.1% | Dec 19, 2025 | A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Predefined Text feature of th... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now