2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15194 | CRITICAL | 9.8 | 1.0% | Dec 29, 2025 | A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality ... |
| CVE-2025-68929 | CRITICAL | 9 | 0.4% | Dec 29, 2025 | Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with spec... |
| CVE-2025-68928 | MEDIUM | 5.4 | 0.2% | Dec 29, 2025 | Frappe CRM is an open-source customer relationship management tool. Prior to version 1.56.2, authenticated users could s... |
| CVE-2025-65570 | CRITICAL | 9.8 | 0.4% | Dec 29, 2025 | A type confusion in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT opcode. When an “instanceof”... |
| CVE-2025-65442 | MEDIUM | 6.1 | 0.3% | Dec 29, 2025 | DOM-based Cross-Site Scripting (XSS) vulnerability in 201206030 novel V3.5.0 allows remote attackers to execute arbitrar... |
| CVE-2025-60458 | MEDIUM | 6.5 | 0.3% | Dec 29, 2025 | UxPlay 1.72 contains a double free vulnerability in its RTSP request handling. A specially crafted RTSP TEARDOWN request... |
| CVE-2025-57462 | MEDIUM | 6.1 | 0.2% | Dec 29, 2025 | Stored cross-site scripting (xss) in machsol machpanel 8.0.32 allows attackers to execute arbitrary web scripts or HTML ... |
| CVE-2025-15193 | HIGH | 8.8 | 0.7% | Dec 29, 2025 | A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. This affects the function sub_423848 of the file /boafrm/f... |
| CVE-2025-15192 | HIGH | 8.8 | 3.4% | Dec 29, 2025 | A security vulnerability has been detected in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_415... |
| CVE-2025-57460 | CRITICAL | 9.8 | 0.4% | Dec 29, 2025 | File upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell. |
| CVE-2025-15191 | HIGH | 8.8 | 3.4% | Dec 29, 2025 | A weakness has been identified in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_4155B4 of the f... |
| CVE-2025-15190 | HIGH | 8.8 | 0.7% | Dec 29, 2025 | A security flaw has been discovered in D-Link DWR-M920 up to 1.1.50. Impacted is the function sub_42261C of the file /bo... |
| CVE-2025-15189 | HIGH | 8.8 | 0.7% | Dec 29, 2025 | A vulnerability was identified in D-Link DWR-M920 up to 1.1.50. This issue affects the function sub_464794 of the file /... |
| CVE-2025-15188 | MEDIUM | 4.8 | 0.2% | Dec 29, 2025 | A vulnerability was determined in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affe... |
| CVE-2025-15187 | MEDIUM | 6.5 | 0.6% | Dec 29, 2025 | A vulnerability was found in GreenCMS up to 2.3. This affects an unknown part of the file /DataController.class.php of t... |
| CVE-2025-15186 | CRITICAL | 9.8 | 0.3% | Dec 29, 2025 | A vulnerability has been found in code-projects Refugee Food Management System 1.0. Affected by this issue is some unkno... |
| CVE-2025-15185 | CRITICAL | 9.8 | 0.3% | Dec 29, 2025 | A flaw has been found in code-projects Refugee Food Management System 1.0. Affected by this vulnerability is an unknown ... |
| CVE-2025-15184 | CRITICAL | 9.8 | 0.3% | Dec 29, 2025 | A vulnerability was detected in code-projects Refugee Food Management System 1.0. Affected is an unknown function of the... |
| CVE-2025-15183 | CRITICAL | 9.8 | 0.4% | Dec 29, 2025 | A security vulnerability has been detected in code-projects Refugee Food Management System 1.0. This impacts an unknown ... |
| CVE-2025-15182 | CRITICAL | 9.8 | 0.3% | Dec 29, 2025 | A weakness has been identified in code-projects Refugee Food Management System 1.0. This affects an unknown function of ... |
| CVE-2025-15181 | CRITICAL | 9.8 | 0.3% | Dec 29, 2025 | A security flaw has been discovered in code-projects Refugee Food Management System 1.0. The impacted element is an unkn... |
| CVE-2025-15180 | HIGH | 7.3 | 1.0% | Dec 29, 2025 | A vulnerability was identified in Tenda WH450 1.0.0.18. The affected element is an unknown function of the file /goform/... |
| CVE-2025-15228 | CRITICAL | 9.8 | 0.5% | Dec 29, 2025 | BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Upload vulnerability, allowing unauthenticated remot... |
| CVE-2025-15227 | HIGH | 8.7 | 0.5% | Dec 29, 2025 | BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote ... |
| CVE-2025-15179 | HIGH | 7.3 | 0.8% | Dec 29, 2025 | A vulnerability was determined in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/qossetting. ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now