2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-68870HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68868MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codeaffairs Wp Tex...
CVE-2025-66869HIGH7.5Buffer overflow vulnerability in function strcat in asan_interceptors.cpp in libming 0.4.8.
CVE-2025-66866HIGH7.5An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial...
CVE-2025-66865HIGH7.5An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause ...
CVE-2025-66864HIGH7.5An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause ...
CVE-2025-66863HIGH7.5An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a d...
CVE-2025-66862HIGH7.5A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a...
CVE-2025-66861LOW2.5An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to caus...
CVE-2025-53627MEDIUM5.3Meshtastic is an open source mesh networking solution. The Meshtastic firmware (starting from version 2.5) introduces as...
CVE-2025-15197HIGH7.2A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vul...
CVE-2025-15196CRITICAL9.8A vulnerability was identified in code-projects Assessment Management 1.0. This affects an unknown part of the file logi...
CVE-2025-69211HIGH7.4Nest is a framework for building scalable Node.js server-side applications. Versions prior to 11.1.11 have a Fastify URL...
CVE-2025-69206MEDIUM4.3Hemmelig is a messing app with with client-side encryption and self-destructing messages. Prior to version 7.3.3, a Serv...
CVE-2025-69201CRITICAL9.8Tugtainer is a self-hosted app for automating updates of docker containers. In versions prior to 1.15.1, arbitary argume...
CVE-2025-69200HIGH7.5phpMyFAQ is an open source FAQ web application. In versions prior to 4.0.16, an unauthenticated remote attacker can trig...
CVE-2025-68951MEDIUM6.1phpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vuln...
CVE-2025-68897CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in Mohammad I. Okfie IF AS Shortcode if-as-short...
CVE-2025-68893MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in HETWORKS WordPress Image shrinker wp-image-shrinker allows Server Si...
CVE-2025-68879HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in councilsoft Conten...
CVE-2025-68878HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in prasadkirpekar Adv...
CVE-2025-68877HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68876HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in INVELITY Invelity ...
CVE-2025-56333CRITICAL9.8An issue in Fossorial fosrl/pangolin v.1.6.2 and before allows a remote attacker to escalate privileges via the 2FA comp...
CVE-2025-15195CRITICAL9.8A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this issue is some unknown functi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now