2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-68619HIGH7.2Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the appstore i...
CVE-2025-68273MEDIUM5.3Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure ...
CVE-2025-55065HIGH7.5CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2025-15410CRITICAL9.8A vulnerability was identified in code-projects Online Guitar Store 1.0. Affected by this issue is some unknown function...
CVE-2025-15409CRITICAL9.8A vulnerability was determined in code-projects Online Guitar Store 1.0. Affected by this vulnerability is an unknown fu...
CVE-2025-68272HIGH7.5Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in...
CVE-2025-66398HIGH8.8Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticate...
CVE-2025-15408CRITICAL9.8A vulnerability was found in code-projects Online Guitar Store 1.0. Affected is an unknown function of the file /admin/C...
CVE-2025-15407CRITICAL9.8A vulnerability has been found in code-projects Online Guitar Store 1.0. This impacts an unknown function of the file /a...
CVE-2025-48769HIGH8.1Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implem...
CVE-2025-48768MEDIUM6.5Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX...
CVE-2025-47411HIGH8.1A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apac...
CVE-2025-15406HIGH8.8A flaw has been found in PHPGurukul Online Course Registration up to 3.1. This affects an unknown function. This manipul...
CVE-2025-14627MEDIUM6.4The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forger...
CVE-2025-14428MEDIUM4.3The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements plugin f...
CVE-2025-66023MEDIUM4.9NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.5 have a Heap-Use-After-Fre...
CVE-2025-15405HIGH8.8A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function. The manipulation results...
CVE-2025-15404HIGH8.8A security vulnerability has been detected in campcodes School File Management System 1.0. The affected element is an un...
CVE-2025-11157HIGH7.8A high-severity remote code execution vulnerability exists in feast-dev/feast version 0.53.0, specifically in the Kubern...
CVE-2025-13820MEDIUM5.3The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provid...
CVE-2025-69413MEDIUM5.3In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username e...
CVE-2025-22203Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2025-22202Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2025-22201Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2025-22200Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now