2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68870 | HIGH | 7.5 | 0.3% | Dec 29, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68868 | MEDIUM | 6.5 | 0.1% | Dec 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codeaffairs Wp Tex... |
| CVE-2025-66869 | HIGH | 7.5 | 0.3% | Dec 29, 2025 | Buffer overflow vulnerability in function strcat in asan_interceptors.cpp in libming 0.4.8. |
| CVE-2025-66866 | HIGH | 7.5 | 0.3% | Dec 29, 2025 | An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial... |
| CVE-2025-66865 | HIGH | 7.5 | 0.3% | Dec 29, 2025 | An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause ... |
| CVE-2025-66864 | HIGH | 7.5 | 0.2% | Dec 29, 2025 | An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause ... |
| CVE-2025-66863 | HIGH | 7.5 | 0.3% | Dec 29, 2025 | An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a d... |
| CVE-2025-66862 | HIGH | 7.5 | 0.3% | Dec 29, 2025 | A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a... |
| CVE-2025-66861 | LOW | 2.5 | 0.1% | Dec 29, 2025 | An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to caus... |
| CVE-2025-53627 | MEDIUM | 5.3 | 0.2% | Dec 29, 2025 | Meshtastic is an open source mesh networking solution. The Meshtastic firmware (starting from version 2.5) introduces as... |
| CVE-2025-15197 | HIGH | 7.2 | 0.3% | Dec 29, 2025 | A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vul... |
| CVE-2025-15196 | CRITICAL | 9.8 | 0.4% | Dec 29, 2025 | A vulnerability was identified in code-projects Assessment Management 1.0. This affects an unknown part of the file logi... |
| CVE-2025-69211 | HIGH | 7.4 | 0.4% | Dec 29, 2025 | Nest is a framework for building scalable Node.js server-side applications. Versions prior to 11.1.11 have a Fastify URL... |
| CVE-2025-69206 | MEDIUM | 4.3 | 0.2% | Dec 29, 2025 | Hemmelig is a messing app with with client-side encryption and self-destructing messages. Prior to version 7.3.3, a Serv... |
| CVE-2025-69201 | CRITICAL | 9.8 | 0.4% | Dec 29, 2025 | Tugtainer is a self-hosted app for automating updates of docker containers. In versions prior to 1.15.1, arbitary argume... |
| CVE-2025-69200 | HIGH | 7.5 | 2.0% | Dec 29, 2025 | phpMyFAQ is an open source FAQ web application. In versions prior to 4.0.16, an unauthenticated remote attacker can trig... |
| CVE-2025-68951 | MEDIUM | 6.1 | 0.2% | Dec 29, 2025 | phpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vuln... |
| CVE-2025-68897 | CRITICAL | 9.9 | 0.3% | Dec 29, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Mohammad I. Okfie IF AS Shortcode if-as-short... |
| CVE-2025-68893 | MEDIUM | 4.9 | 0.1% | Dec 29, 2025 | Server-Side Request Forgery (SSRF) vulnerability in HETWORKS WordPress Image shrinker wp-image-shrinker allows Server Si... |
| CVE-2025-68879 | HIGH | 7.1 | 0.1% | Dec 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in councilsoft Conten... |
| CVE-2025-68878 | HIGH | 7.1 | 0.1% | Dec 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in prasadkirpekar Adv... |
| CVE-2025-68877 | HIGH | 7.5 | 0.3% | Dec 29, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68876 | HIGH | 7.1 | 0.1% | Dec 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in INVELITY Invelity ... |
| CVE-2025-56333 | CRITICAL | 9.8 | 0.4% | Dec 29, 2025 | An issue in Fossorial fosrl/pangolin v.1.6.2 and before allows a remote attacker to escalate privileges via the 2FA comp... |
| CVE-2025-15195 | CRITICAL | 9.8 | 0.4% | Dec 29, 2025 | A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this issue is some unknown functi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now