2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-69217HIGH7.7coturn is a free open source implementation of TURN and STUN Server. Versions 4.6.2r5 through 4.7.0-r4 have a bad random...
CVE-2025-15213MEDIUM4.3A vulnerability has been found in code-projects Student File Management System 1.0. The affected element is an unknown f...
CVE-2025-15212CRITICAL9.8A vulnerability was detected in code-projects Refugee Food Management System 1.0. This issue affects some unknown proces...
CVE-2025-15211CRITICAL9.8A flaw has been found in code-projects Refugee Food Management System 1.0. Impacted is an unknown function of the file /...
CVE-2025-68499MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs...
CVE-2025-68498MEDIUM6.5Missing Authorization vulnerability in Crocoblock JetTabs jet-tabs allows Exploiting Incorrectly Configured Access Contr...
CVE-2025-68120MEDIUM5.4To prevent unexpected untrusted code execution, the Visual Studio Code Go extension is now disabled in Restricted Mode.
CVE-2025-68040MEDIUM6.5Insertion of Sensitive Information Into Sent Data vulnerability in weDevs WP Project Manager wedevs-project-manager allo...
CVE-2025-68036HIGH7.5Missing Authorization vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Accessing Functionality Not Properly...
CVE-2025-23554HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jakub Glos Off Pag...
CVE-2025-23550HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kemal YAZICI Produ...
CVE-2025-23469HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sleekplan Sleekpla...
CVE-2025-23458HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rakessh Ads24 Lite...
CVE-2025-15210CRITICAL9.8A security vulnerability has been detected in code-projects Refugee Food Management System 1.0. This vulnerability affec...
CVE-2025-15284MEDIUM6.3Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1. Summary...
CVE-2025-15209CRITICAL9.8A weakness has been identified in code-projects Refugee Food Management System 1.0. This affects an unknown part of the ...
CVE-2025-15208CRITICAL9.8A security flaw has been discovered in code-projects Refugee Food Management System 1.0. Affected by this issue is some ...
CVE-2025-68860CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Mobile Builder Mobile builder mobile-builder a...
CVE-2025-68607MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hiroaki Miyashita ...
CVE-2025-68562CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG allows Upload a Web Shell to a Web Ser...
CVE-2025-68504MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSear...
CVE-2025-68503MEDIUM6.5Missing Authorization vulnerability in Crocoblock JetBlog jet-blog allows Exploiting Incorrectly Configured Access Contr...
CVE-2025-68502MEDIUM4.3Authorization Bypass Through User-Controlled Key vulnerability in Crocoblock JetPopup jet-popup allows Exploiting Incorr...
CVE-2025-15207CRITICAL9.8A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file ...
CVE-2025-15206CRITICAL9.8A flaw has been found in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /admin/a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now