2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69205 | MEDIUM | 6.3 | 0.1% | Dec 29, 2025 | Micro Registration Utility (µURU) is a telephone self registration utility based on asterisk. In versions up to and incl... |
| CVE-2025-15205 | HIGH | 8.8 | 0.3% | Dec 29, 2025 | A vulnerability was identified in code-projects Student File Management System 1.0. Affected by this vulnerability is an... |
| CVE-2025-15204 | MEDIUM | 4.8 | 0.2% | Dec 29, 2025 | A vulnerability was determined in SohuTV CacheCloud up to 3.2.0. Affected is the function doQuartzList of the file src/m... |
| CVE-2025-69202 | MEDIUM | 6.5 | 0.3% | Dec 29, 2025 | Axios Cache Interceptor is a cache interceptor for axios. Prior to version 1.11.1, when a server calls an upstream servi... |
| CVE-2025-15203 | MEDIUM | 4.8 | 0.2% | Dec 29, 2025 | A vulnerability was found in SohuTV CacheCloud up to 3.2.0. This impacts the function index of the file src/main/java/co... |
| CVE-2025-15202 | MEDIUM | 4.8 | 0.2% | Dec 29, 2025 | A vulnerability has been found in SohuTV CacheCloud up to 3.2.0. This affects the function taskQueueList of the file src... |
| CVE-2025-14175 | MEDIUM | 6.5 | 0.3% | Dec 29, 2025 | A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling ... |
| CVE-2025-68706 | CRITICAL | 9.8 | 4.2% | Dec 29, 2025 | A stack-based buffer overflow exists in the GoAhead-Webs HTTP daemon on KuWFi 4G LTE AC900 devices with firmware 1.0.13.... |
| CVE-2025-68431 | HIGH | 7.1 | 0.3% | Dec 29, 2025 | libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the ... |
| CVE-2025-67255 | HIGH | 8.8 | 0.9% | Dec 29, 2025 | In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to ... |
| CVE-2025-67254 | HIGH | 7.5 | 1.7% | Dec 29, 2025 | NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Directory Traversal in /admin/coreconfigsnapshots.php. |
| CVE-2025-15201 | MEDIUM | 5.4 | 0.2% | Dec 29, 2025 | A flaw has been found in SohuTV CacheCloud up to 3.2.0. The impacted element is the function redirectNoPower of the file... |
| CVE-2025-15200 | MEDIUM | 4.8 | 0.2% | Dec 29, 2025 | A vulnerability was detected in SohuTV CacheCloud up to 3.2.0. The affected element is the function getExceptionStatisti... |
| CVE-2025-15199 | HIGH | 8.8 | 0.2% | Dec 29, 2025 | A security vulnerability has been detected in code-projects College Notes Uploading System 1.0. Impacted is an unknown f... |
| CVE-2025-14728 | MEDIUM | 6.8 | 0.5% | Dec 29, 2025 | Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue clie... |
| CVE-2025-14280 | MEDIUM | 5.3 | 0.4% | Dec 29, 2025 | The PixelYourSite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2025-13592 | HIGH | 7.2 | 0.8% | Dec 29, 2025 | The Advanced Ads plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.14 vi... |
| CVE-2025-68861 | HIGH | 7.1 | 0.2% | Dec 29, 2025 | Missing Authorization vulnerability in pluginoptimizer Plugin Optimizer plugin-optimizer allows Exploiting Incorrectly C... |
| CVE-2025-66877 | HIGH | 7.5 | 0.3% | Dec 29, 2025 | Buffer overflow vulnerability in function dcputchar in decompile.c in libming 0.4.8. |
| CVE-2025-55064 | MEDIUM | 4.8 | 0.1% | Dec 29, 2025 | CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') |
| CVE-2025-55063 | MEDIUM | 4.8 | 0.1% | Dec 29, 2025 | CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') |
| CVE-2025-55062 | MEDIUM | 4.8 | 0.1% | Dec 29, 2025 | CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') |
| CVE-2025-55061 | HIGH | 8.8 | 0.3% | Dec 29, 2025 | CWE-434 Unrestricted Upload of File with Dangerous Type |
| CVE-2025-55060 | MEDIUM | 6.1 | 0.1% | Dec 29, 2025 | CWE-601 URL Redirection to Untrusted Site ('Open Redirect') |
| CVE-2025-15198 | CRITICAL | 9.8 | 0.3% | Dec 29, 2025 | A weakness has been identified in code-projects College Notes Uploading System 1.0. This issue affects some unknown proc... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now