2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69217 | HIGH | 7.7 | 0.4% | Dec 30, 2025 | coturn is a free open source implementation of TURN and STUN Server. Versions 4.6.2r5 through 4.7.0-r4 have a bad random... |
| CVE-2025-15213 | MEDIUM | 4.3 | 0.3% | Dec 30, 2025 | A vulnerability has been found in code-projects Student File Management System 1.0. The affected element is an unknown f... |
| CVE-2025-15212 | CRITICAL | 9.8 | 0.3% | Dec 30, 2025 | A vulnerability was detected in code-projects Refugee Food Management System 1.0. This issue affects some unknown proces... |
| CVE-2025-15211 | CRITICAL | 9.8 | 0.3% | Dec 30, 2025 | A flaw has been found in code-projects Refugee Food Management System 1.0. Impacted is an unknown function of the file /... |
| CVE-2025-68499 | MEDIUM | 6.5 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs... |
| CVE-2025-68498 | MEDIUM | 6.5 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in Crocoblock JetTabs jet-tabs allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2025-68120 | MEDIUM | 5.4 | 0.4% | Dec 30, 2025 | To prevent unexpected untrusted code execution, the Visual Studio Code Go extension is now disabled in Restricted Mode. |
| CVE-2025-68040 | MEDIUM | 6.5 | 0.2% | Dec 30, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in weDevs WP Project Manager wedevs-project-manager allo... |
| CVE-2025-68036 | HIGH | 7.5 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Accessing Functionality Not Properly... |
| CVE-2025-23554 | HIGH | 7.1 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jakub Glos Off Pag... |
| CVE-2025-23550 | HIGH | 7.1 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kemal YAZICI Produ... |
| CVE-2025-23469 | HIGH | 7.1 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sleekplan Sleekpla... |
| CVE-2025-23458 | HIGH | 7.1 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rakessh Ads24 Lite... |
| CVE-2025-15210 | CRITICAL | 9.8 | 0.3% | Dec 30, 2025 | A security vulnerability has been detected in code-projects Refugee Food Management System 1.0. This vulnerability affec... |
| CVE-2025-15284 | MEDIUM | 6.3 | 0.4% | Dec 29, 2025 | Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1. Summary... |
| CVE-2025-15209 | CRITICAL | 9.8 | 0.3% | Dec 29, 2025 | A weakness has been identified in code-projects Refugee Food Management System 1.0. This affects an unknown part of the ... |
| CVE-2025-15208 | CRITICAL | 9.8 | 0.3% | Dec 29, 2025 | A security flaw has been discovered in code-projects Refugee Food Management System 1.0. Affected by this issue is some ... |
| CVE-2025-68860 | CRITICAL | 9.8 | 0.5% | Dec 29, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Mobile Builder Mobile builder mobile-builder a... |
| CVE-2025-68607 | MEDIUM | 6.5 | 0.2% | Dec 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hiroaki Miyashita ... |
| CVE-2025-68562 | CRITICAL | 9.9 | 0.4% | Dec 29, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG allows Upload a Web Shell to a Web Ser... |
| CVE-2025-68504 | MEDIUM | 6.5 | 0.2% | Dec 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSear... |
| CVE-2025-68503 | MEDIUM | 6.5 | 0.3% | Dec 29, 2025 | Missing Authorization vulnerability in Crocoblock JetBlog jet-blog allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2025-68502 | MEDIUM | 4.3 | 0.2% | Dec 29, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Crocoblock JetPopup jet-popup allows Exploiting Incorr... |
| CVE-2025-15207 | CRITICAL | 9.8 | 0.4% | Dec 29, 2025 | A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file ... |
| CVE-2025-15206 | CRITICAL | 9.8 | 0.4% | Dec 29, 2025 | A flaw has been found in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /admin/a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now