2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67709 | MEDIUM | 6.1 | 0.2% | Dec 31, 2025 | There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co... |
| CVE-2025-67708 | MEDIUM | 6.1 | 0.2% | Dec 31, 2025 | There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co... |
| CVE-2025-67707 | MEDIUM | 5.6 | 0.2% | Dec 31, 2025 | ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a rem... |
| CVE-2025-67706 | MEDIUM | 5.6 | 0.3% | Dec 31, 2025 | ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a rem... |
| CVE-2025-67705 | MEDIUM | 6.1 | 0.2% | Dec 31, 2025 | There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co... |
| CVE-2025-67704 | MEDIUM | 6.1 | 0.2% | Dec 31, 2025 | There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co... |
| CVE-2025-67703 | MEDIUM | 6.1 | 0.2% | Dec 31, 2025 | There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co... |
| CVE-2025-69288 | CRITICAL | 9.1 | 0.7% | Dec 31, 2025 | Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user... |
| CVE-2025-69286 | CRITICAL | 9.8 | 0.5% | Dec 31, 2025 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecu... |
| CVE-2025-68700 | HIGH | 8.8 | 0.5% | Dec 31, 2025 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged aut... |
| CVE-2025-34469 | HIGH | 7.5 | 0.6% | Dec 31, 2025 | Cowrie versions prior to 2.9.0 contain a server-side request forgery (SSRF) vulnerability in the emulated shell implemen... |
| CVE-2025-15398 | HIGH | 8.1 | 0.5% | Dec 31, 2025 | A security vulnerability has been detected in Uasoft badaso up to 2.9.7. Affected is the function forgetPassword of the ... |
| CVE-2025-53235 | HIGH | 7.1 | 0.2% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osuthorpe Easy Soc... |
| CVE-2025-66148 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Conformer for Elementor conformer-elementor allows Exploiting Incorrect... |
| CVE-2025-66146 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Logger for Elementor logger-elementor allows Exploiting Incorrectly Con... |
| CVE-2025-66145 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Worker for WPBakery worker-wpbakery allows Exploiting Incorrectly Confi... |
| CVE-2025-66144 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | Missing Authorization vulnerability in merkulove Worker for Elementor worker-elementor allows Exploiting Incorrectly Con... |
| CVE-2025-52739 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Sala allows ... |
| CVE-2025-50053 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nebelhorn Blappsta... |
| CVE-2025-47566 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomSounds allows ... |
| CVE-2025-31054 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Themefy Bloggie allows Reflected XSS.This issue affects Bloggie: from... |
| CVE-2025-30628 | HIGH | 8.5 | 0.2% | Dec 31, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Aff... |
| CVE-2025-28973 | MEDIUM | 6.5 | 0.3% | Dec 31, 2025 | Path Traversal: '.../...//' vulnerability in AA-Team Pro Bulk Watermark Plugin for WordPress pro-watermark allows Path T... |
| CVE-2025-28949 | HIGH | 8.5 | 0.2% | Dec 31, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codedraft Mediabay... |
| CVE-2025-23757 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proloy Chakroborty... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now