2025 CVE Vulnerabilities
45,158 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14820 | — | — | — | Dec 25, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-14715 | — | — | — | Dec 25, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-15088 | MEDIUM | 6.3 | 0.2% | Dec 25, 2025 | A vulnerability was detected in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is the function postilService.lo... |
| CVE-2025-15087 | MEDIUM | 4.3 | 0.2% | Dec 25, 2025 | A security vulnerability has been detected in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function submitOrderPa... |
| CVE-2025-15086 | MEDIUM | 4.3 | 0.3% | Dec 25, 2025 | A weakness has been identified in youlaitech youlai-mall 1.0.0/2.0.0. This impacts the function getMemberByMobile of the... |
| CVE-2025-68936 | MEDIUM | 6.1 | 0.2% | Dec 25, 2025 | ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer. |
| CVE-2025-68935 | MEDIUM | 6.1 | 0.2% | Dec 25, 2025 | ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to D... |
| CVE-2025-15085 | HIGH | 8.1 | 0.3% | Dec 25, 2025 | A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of th... |
| CVE-2025-15084 | LOW | 3.1 | 0.2% | Dec 25, 2025 | A vulnerability was identified in youlaitech youlai-mall 1.0.0/2.0.0. The impacted element is the function orderService.... |
| CVE-2025-15083 | MEDIUM | 4.6 | 0.2% | Dec 25, 2025 | A vulnerability was determined in TOZED ZLT M30s up to 1.47. The affected element is an unknown function of the componen... |
| CVE-2025-15082 | HIGH | 7.5 | 0.6% | Dec 25, 2025 | A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/proc_post o... |
| CVE-2025-15081 | MEDIUM | 6.3 | 2.3% | Dec 25, 2025 | A vulnerability has been found in JD Cloud BE6500 4.4.1.r4308. This issue affects the function sub_4780 of the file /jdc... |
| CVE-2025-2406 | HIGH | 7.6 | 0.3% | Dec 25, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Com... |
| CVE-2025-2405 | HIGH | 7.6 | 0.3% | Dec 25, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Com... |
| CVE-2025-2307 | HIGH | 7.6 | 0.3% | Dec 25, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Com... |
| CVE-2025-66443 | MEDIUM | 5.3 | 0.3% | Dec 25, 2025 | Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improp... |
| CVE-2025-66379 | HIGH | 7.5 | 0.3% | Dec 25, 2025 | Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trig... |
| CVE-2025-66378 | HIGH | 7.5 | 0.2% | Dec 25, 2025 | Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacke... |
| CVE-2025-66377 | HIGH | 7.5 | 0.2% | Dec 25, 2025 | Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an att... |
| CVE-2025-59683 | CRITICAL | 9.1 | 0.3% | Dec 25, 2025 | Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, w... |
| CVE-2025-49088 | MEDIUM | 5.9 | 0.3% | Dec 25, 2025 | Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join... |
| CVE-2025-48704 | HIGH | 7.5 | 0.3% | Dec 25, 2025 | Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trig... |
| CVE-2025-32096 | HIGH | 7.5 | 0.3% | Dec 25, 2025 | Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigg... |
| CVE-2025-32095 | HIGH | 7.5 | 0.4% | Dec 25, 2025 | Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a softwa... |
| CVE-2025-15078 | CRITICAL | 9.8 | 0.3% | Dec 25, 2025 | A vulnerability was detected in itsourcecode Student Management System 1.0. The impacted element is an unknown function ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now