2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66866 | HIGH | 7.5 | 0.3% | Dec 29, 2025 | An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial... |
| CVE-2025-66865 | HIGH | 7.5 | 0.3% | Dec 29, 2025 | An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause ... |
| CVE-2025-66864 | HIGH | 7.5 | 0.2% | Dec 29, 2025 | An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause ... |
| CVE-2025-66863 | HIGH | 7.5 | 0.3% | Dec 29, 2025 | An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a d... |
| CVE-2025-66862 | HIGH | 7.5 | 0.3% | Dec 29, 2025 | A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a... |
| CVE-2025-66861 | LOW | 2.5 | 0.1% | Dec 29, 2025 | An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to caus... |
| CVE-2025-53627 | MEDIUM | 5.3 | 0.2% | Dec 29, 2025 | Meshtastic is an open source mesh networking solution. The Meshtastic firmware (starting from version 2.5) introduces as... |
| CVE-2025-15197 | HIGH | 7.2 | 0.3% | Dec 29, 2025 | A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vul... |
| CVE-2025-15196 | CRITICAL | 9.8 | 0.4% | Dec 29, 2025 | A vulnerability was identified in code-projects Assessment Management 1.0. This affects an unknown part of the file logi... |
| CVE-2025-69211 | HIGH | 7.4 | 0.4% | Dec 29, 2025 | Nest is a framework for building scalable Node.js server-side applications. Versions prior to 11.1.11 have a Fastify URL... |
| CVE-2025-69206 | MEDIUM | 4.3 | 0.2% | Dec 29, 2025 | Hemmelig is a messing app with with client-side encryption and self-destructing messages. Prior to version 7.3.3, a Serv... |
| CVE-2025-69201 | CRITICAL | 9.8 | 0.4% | Dec 29, 2025 | Tugtainer is a self-hosted app for automating updates of docker containers. In versions prior to 1.15.1, arbitary argume... |
| CVE-2025-69200 | HIGH | 7.5 | 2.0% | Dec 29, 2025 | phpMyFAQ is an open source FAQ web application. In versions prior to 4.0.16, an unauthenticated remote attacker can trig... |
| CVE-2025-68951 | MEDIUM | 6.1 | 0.2% | Dec 29, 2025 | phpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vuln... |
| CVE-2025-68897 | CRITICAL | 9.9 | 0.3% | Dec 29, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Mohammad I. Okfie IF AS Shortcode if-as-short... |
| CVE-2025-68893 | MEDIUM | 4.9 | 0.1% | Dec 29, 2025 | Server-Side Request Forgery (SSRF) vulnerability in HETWORKS WordPress Image shrinker wp-image-shrinker allows Server Si... |
| CVE-2025-68879 | HIGH | 7.1 | 0.1% | Dec 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in councilsoft Conten... |
| CVE-2025-68878 | HIGH | 7.1 | 0.1% | Dec 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in prasadkirpekar Adv... |
| CVE-2025-68877 | HIGH | 7.5 | 0.3% | Dec 29, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68876 | HIGH | 7.1 | 0.1% | Dec 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in INVELITY Invelity ... |
| CVE-2025-56333 | CRITICAL | 9.8 | 0.4% | Dec 29, 2025 | An issue in Fossorial fosrl/pangolin v.1.6.2 and before allows a remote attacker to escalate privileges via the 2FA comp... |
| CVE-2025-15195 | CRITICAL | 9.8 | 0.4% | Dec 29, 2025 | A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this issue is some unknown functi... |
| CVE-2025-15194 | CRITICAL | 9.8 | 1.0% | Dec 29, 2025 | A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality ... |
| CVE-2025-68929 | CRITICAL | 9 | 0.4% | Dec 29, 2025 | Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with spec... |
| CVE-2025-68928 | MEDIUM | 5.4 | 0.2% | Dec 29, 2025 | Frappe CRM is an open-source customer relationship management tool. Prior to version 1.56.2, authenticated users could s... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now