2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-69202MEDIUM6.5Axios Cache Interceptor is a cache interceptor for axios. Prior to version 1.11.1, when a server calls an upstream servi...
CVE-2025-15203MEDIUM4.8A vulnerability was found in SohuTV CacheCloud up to 3.2.0. This impacts the function index of the file src/main/java/co...
CVE-2025-15202MEDIUM4.8A vulnerability has been found in SohuTV CacheCloud up to 3.2.0. This affects the function taskQueueList of the file src...
CVE-2025-14175MEDIUM6.5A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling ...
CVE-2025-68706CRITICAL9.8A stack-based buffer overflow exists in the GoAhead-Webs HTTP daemon on KuWFi 4G LTE AC900 devices with firmware 1.0.13....
CVE-2025-68431HIGH7.1libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the ...
CVE-2025-67255HIGH8.8In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to ...
CVE-2025-67254HIGH7.5NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Directory Traversal in /admin/coreconfigsnapshots.php.
CVE-2025-15201MEDIUM5.4A flaw has been found in SohuTV CacheCloud up to 3.2.0. The impacted element is the function redirectNoPower of the file...
CVE-2025-15200MEDIUM4.8A vulnerability was detected in SohuTV CacheCloud up to 3.2.0. The affected element is the function getExceptionStatisti...
CVE-2025-15199HIGH8.8A security vulnerability has been detected in code-projects College Notes Uploading System 1.0. Impacted is an unknown f...
CVE-2025-14728MEDIUM6.8Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue clie...
CVE-2025-14280MEDIUM5.3The PixelYourSite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2025-13592HIGH7.2The Advanced Ads plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.14 vi...
CVE-2025-68861HIGH7.1Missing Authorization vulnerability in pluginoptimizer Plugin Optimizer plugin-optimizer allows Exploiting Incorrectly C...
CVE-2025-66877HIGH7.5Buffer overflow vulnerability in function dcputchar in decompile.c in libming 0.4.8.
CVE-2025-55064MEDIUM4.8CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
CVE-2025-55063MEDIUM4.8CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
CVE-2025-55062MEDIUM4.8CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
CVE-2025-55061HIGH8.8CWE-434 Unrestricted Upload of File with Dangerous Type
CVE-2025-55060MEDIUM6.1CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
CVE-2025-15198CRITICAL9.8A weakness has been identified in code-projects College Notes Uploading System 1.0. This issue affects some unknown proc...
CVE-2025-68870HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68868MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codeaffairs Wp Tex...
CVE-2025-66869HIGH7.5Buffer overflow vulnerability in function strcat in asan_interceptors.cpp in libming 0.4.8.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now