2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-69205MEDIUM6.3Micro Registration Utility (µURU) is a telephone self registration utility based on asterisk. In versions up to and incl...
CVE-2025-15205HIGH8.8A vulnerability was identified in code-projects Student File Management System 1.0. Affected by this vulnerability is an...
CVE-2025-15204MEDIUM4.8A vulnerability was determined in SohuTV CacheCloud up to 3.2.0. Affected is the function doQuartzList of the file src/m...
CVE-2025-69202MEDIUM6.5Axios Cache Interceptor is a cache interceptor for axios. Prior to version 1.11.1, when a server calls an upstream servi...
CVE-2025-15203MEDIUM4.8A vulnerability was found in SohuTV CacheCloud up to 3.2.0. This impacts the function index of the file src/main/java/co...
CVE-2025-15202MEDIUM4.8A vulnerability has been found in SohuTV CacheCloud up to 3.2.0. This affects the function taskQueueList of the file src...
CVE-2025-14175MEDIUM6.5A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling ...
CVE-2025-68706CRITICAL9.8A stack-based buffer overflow exists in the GoAhead-Webs HTTP daemon on KuWFi 4G LTE AC900 devices with firmware 1.0.13....
CVE-2025-68431HIGH7.1libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the ...
CVE-2025-67255HIGH8.8In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to ...
CVE-2025-67254HIGH7.5NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Directory Traversal in /admin/coreconfigsnapshots.php.
CVE-2025-15201MEDIUM5.4A flaw has been found in SohuTV CacheCloud up to 3.2.0. The impacted element is the function redirectNoPower of the file...
CVE-2025-15200MEDIUM4.8A vulnerability was detected in SohuTV CacheCloud up to 3.2.0. The affected element is the function getExceptionStatisti...
CVE-2025-15199HIGH8.8A security vulnerability has been detected in code-projects College Notes Uploading System 1.0. Impacted is an unknown f...
CVE-2025-14728MEDIUM6.8Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue clie...
CVE-2025-14280MEDIUM5.3The PixelYourSite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2025-13592HIGH7.2The Advanced Ads plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.14 vi...
CVE-2025-68861HIGH7.1Missing Authorization vulnerability in pluginoptimizer Plugin Optimizer plugin-optimizer allows Exploiting Incorrectly C...
CVE-2025-66877HIGH7.5Buffer overflow vulnerability in function dcputchar in decompile.c in libming 0.4.8.
CVE-2025-55064MEDIUM4.8CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
CVE-2025-55063MEDIUM4.8CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
CVE-2025-55062MEDIUM4.8CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
CVE-2025-55061HIGH8.8CWE-434 Unrestricted Upload of File with Dangerous Type
CVE-2025-55060MEDIUM6.1CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
CVE-2025-15198CRITICAL9.8A weakness has been identified in code-projects College Notes Uploading System 1.0. This issue affects some unknown proc...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now