2025 CVE Vulnerabilities

45,158 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14820Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-14715Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-15088MEDIUM6.3A vulnerability was detected in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is the function postilService.lo...
CVE-2025-15087MEDIUM4.3A security vulnerability has been detected in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function submitOrderPa...
CVE-2025-15086MEDIUM4.3A weakness has been identified in youlaitech youlai-mall 1.0.0/2.0.0. This impacts the function getMemberByMobile of the...
CVE-2025-68936MEDIUM6.1ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.
CVE-2025-68935MEDIUM6.1ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to D...
CVE-2025-15085HIGH8.1A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of th...
CVE-2025-15084LOW3.1A vulnerability was identified in youlaitech youlai-mall 1.0.0/2.0.0. The impacted element is the function orderService....
CVE-2025-15083MEDIUM4.6A vulnerability was determined in TOZED ZLT M30s up to 1.47. The affected element is an unknown function of the componen...
CVE-2025-15082HIGH7.5A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/proc_post o...
CVE-2025-15081MEDIUM6.3A vulnerability has been found in JD Cloud BE6500 4.4.1.r4308. This issue affects the function sub_4780 of the file /jdc...
CVE-2025-2406HIGH7.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Com...
CVE-2025-2405HIGH7.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Com...
CVE-2025-2307HIGH7.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Com...
CVE-2025-66443MEDIUM5.3Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improp...
CVE-2025-66379HIGH7.5Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trig...
CVE-2025-66378HIGH7.5Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacke...
CVE-2025-66377HIGH7.5Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an att...
CVE-2025-59683CRITICAL9.1Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, w...
CVE-2025-49088MEDIUM5.9Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join...
CVE-2025-48704HIGH7.5Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trig...
CVE-2025-32096HIGH7.5Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigg...
CVE-2025-32095HIGH7.5Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a softwa...
CVE-2025-15078CRITICAL9.8A vulnerability was detected in itsourcecode Student Management System 1.0. The impacted element is an unknown function ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now