2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68619 | HIGH | 7.2 | 0.6% | Jan 1, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the appstore i... |
| CVE-2025-68273 | MEDIUM | 5.3 | 0.3% | Jan 1, 2026 | Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure ... |
| CVE-2025-55065 | HIGH | 7.5 | 0.2% | Jan 1, 2026 | CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
| CVE-2025-15410 | CRITICAL | 9.8 | 0.3% | Jan 1, 2026 | A vulnerability was identified in code-projects Online Guitar Store 1.0. Affected by this issue is some unknown function... |
| CVE-2025-15409 | CRITICAL | 9.8 | 0.4% | Jan 1, 2026 | A vulnerability was determined in code-projects Online Guitar Store 1.0. Affected by this vulnerability is an unknown fu... |
| CVE-2025-68272 | HIGH | 7.5 | 0.5% | Jan 1, 2026 | Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in... |
| CVE-2025-66398 | HIGH | 8.8 | 17.9% | Jan 1, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticate... |
| CVE-2025-15408 | CRITICAL | 9.8 | 0.3% | Jan 1, 2026 | A vulnerability was found in code-projects Online Guitar Store 1.0. Affected is an unknown function of the file /admin/C... |
| CVE-2025-15407 | CRITICAL | 9.8 | 0.3% | Jan 1, 2026 | A vulnerability has been found in code-projects Online Guitar Store 1.0. This impacts an unknown function of the file /a... |
| CVE-2025-48769 | HIGH | 8.1 | 1.5% | Jan 1, 2026 | Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implem... |
| CVE-2025-48768 | MEDIUM | 6.5 | 0.8% | Jan 1, 2026 | Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX... |
| CVE-2025-47411 | HIGH | 8.1 | 14.8% | Jan 1, 2026 | A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apac... |
| CVE-2025-15406 | HIGH | 8.8 | 0.4% | Jan 1, 2026 | A flaw has been found in PHPGurukul Online Course Registration up to 3.1. This affects an unknown function. This manipul... |
| CVE-2025-14627 | MEDIUM | 6.4 | 0.2% | Jan 1, 2026 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forger... |
| CVE-2025-14428 | MEDIUM | 4.3 | 0.3% | Jan 1, 2026 | The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements plugin f... |
| CVE-2025-66023 | MEDIUM | 4.9 | 0.3% | Jan 1, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.5 have a Heap-Use-After-Fre... |
| CVE-2025-15405 | HIGH | 8.8 | 0.2% | Jan 1, 2026 | A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function. The manipulation results... |
| CVE-2025-15404 | HIGH | 8.8 | 0.3% | Jan 1, 2026 | A security vulnerability has been detected in campcodes School File Management System 1.0. The affected element is an un... |
| CVE-2025-11157 | HIGH | 7.8 | 0.3% | Jan 1, 2026 | A high-severity remote code execution vulnerability exists in feast-dev/feast version 0.53.0, specifically in the Kubern... |
| CVE-2025-13820 | MEDIUM | 5.3 | 0.2% | Jan 1, 2026 | The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provid... |
| CVE-2025-69413 | MEDIUM | 5.3 | 0.4% | Jan 1, 2026 | In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username e... |
| CVE-2025-22203 | — | — | — | Jan 1, 2026 | Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. |
| CVE-2025-22202 | — | — | — | Jan 1, 2026 | Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. |
| CVE-2025-22201 | — | — | — | Jan 1, 2026 | Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. |
| CVE-2025-22200 | — | — | — | Jan 1, 2026 | Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now