2025 CVE Vulnerabilities
45,155 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52599 | MEDIUM | 6.5 | 0.2% | Dec 26, 2025 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io... |
| CVE-2025-52598 | LOW | 3.7 | 0.2% | Dec 26, 2025 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io... |
| CVE-2025-68945 | MEDIUM | 5.3 | 0.3% | Dec 26, 2025 | In Gitea before 1.21.2, an anonymous user can visit a private user's project. |
| CVE-2025-68944 | MEDIUM | 5.3 | 0.3% | Dec 26, 2025 | Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package... |
| CVE-2025-68943 | MEDIUM | 5.3 | 0.3% | Dec 26, 2025 | Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users... |
| CVE-2025-15099 | CRITICAL | 9.8 | 0.7% | Dec 26, 2025 | A vulnerability was identified in simstudioai sim up to 0.5.27. This vulnerability affects unknown code of the file apps... |
| CVE-2025-68942 | MEDIUM | 5.4 | 0.2% | Dec 26, 2025 | Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text... |
| CVE-2025-68941 | MEDIUM | 5.3 | 0.2% | Dec 26, 2025 | Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public res... |
| CVE-2025-68940 | MEDIUM | 5.3 | 0.3% | Dec 26, 2025 | In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request. |
| CVE-2025-68939 | MEDIUM | 5.3 | 0.3% | Dec 26, 2025 | Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via... |
| CVE-2025-15098 | MEDIUM | 6.3 | 0.3% | Dec 26, 2025 | A vulnerability was determined in YunaiV yudao-cloud up to 2025.11. This affects the function BpmHttpCallbackTrigger/Bpm... |
| CVE-2025-15097 | HIGH | 7.3 | 0.5% | Dec 26, 2025 | A vulnerability was found in Alteryx Server. Affected by this issue is some unknown functionality of the file /gallery/a... |
| CVE-2025-15095 | LOW | 3.5 | 0.3% | Dec 26, 2025 | A security vulnerability has been detected in postmanlabs httpbin up to 0.6.1. This affects an unknown function of the f... |
| CVE-2025-68938 | MEDIUM | 5.3 | 0.3% | Dec 26, 2025 | Gitea before 1.25.2 mishandles authorization for deletion of releases. |
| CVE-2025-15094 | MEDIUM | 6.1 | 0.4% | Dec 26, 2025 | A weakness has been identified in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The impacted element ... |
| CVE-2025-15093 | MEDIUM | 6.1 | 0.4% | Dec 26, 2025 | A security flaw has been discovered in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The affected ele... |
| CVE-2025-15092 | CRITICAL | 9.8 | 0.8% | Dec 26, 2025 | A vulnerability was identified in UTT 进取 512W up to 1.7.7-171114. Impacted is the function strcpy of the file /goform/Co... |
| CVE-2025-68937 | CRITICAL | 9.5 | 0.5% | Dec 26, 2025 | Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of... |
| CVE-2025-15091 | CRITICAL | 9.8 | 0.8% | Dec 26, 2025 | A vulnerability was determined in UTT 进取 512W up to 1.7.7-171114. This issue affects the function strcpy of the file /go... |
| CVE-2025-14913 | MEDIUM | 5.3 | 0.3% | Dec 26, 2025 | The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unau... |
| CVE-2025-15090 | CRITICAL | 9.8 | 0.7% | Dec 25, 2025 | A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This vulnerability affects the function strcpy of the file ... |
| CVE-2025-15089 | CRITICAL | 9.8 | 0.7% | Dec 25, 2025 | A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. This affects the function strcpy of the file /goform/A... |
| CVE-2025-14820 | — | — | — | Dec 25, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-14715 | — | — | — | Dec 25, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-15088 | MEDIUM | 6.3 | 0.2% | Dec 25, 2025 | A vulnerability was detected in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is the function postilService.lo... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now