2025 CVE Vulnerabilities
45,158 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15077 | CRITICAL | 9.8 | 0.3% | Dec 25, 2025 | A security vulnerability has been detected in itsourcecode Student Management System 1.0. The affected element is an unk... |
| CVE-2025-15076 | HIGH | 7.3 | 0.6% | Dec 25, 2025 | A weakness has been identified in Tenda CH22 1.0.0.1. Impacted is an unknown function of the file /public/. Executing a ... |
| CVE-2025-15075 | CRITICAL | 9.8 | 0.4% | Dec 25, 2025 | A security flaw has been discovered in itsourcecode Student Management System 1.0. This issue affects some unknown proce... |
| CVE-2025-15074 | CRITICAL | 9.8 | 0.4% | Dec 25, 2025 | A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unkno... |
| CVE-2025-68922 | HIGH | 7.4 | 0.2% | Dec 25, 2025 | OpenOps before 0.6.11 allows remote code execution in the Terraform block. |
| CVE-2025-15073 | CRITICAL | 9.8 | 0.4% | Dec 24, 2025 | A vulnerability was determined in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of ... |
| CVE-2025-68920 | HIGH | 8.9 | 0.4% | Dec 24, 2025 | C-Kermit (aka ckermit) through 10.0 Beta.12 (aka 416-beta12) before 244644d allows a remote Kermit system to overwrite f... |
| CVE-2025-8769 | CRITICAL | 9.8 | 0.9% | Dec 24, 2025 | Telenium Online Web Application is vulnerable due to a Perl script that is called to load the login page. Due to improp... |
| CVE-2025-68919 | MEDIUM | 5.6 | 0.1% | Dec 24, 2025 | Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when ... |
| CVE-2025-68917 | MEDIUM | 6.4 | 0.2% | Dec 24, 2025 | ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer. |
| CVE-2025-68916 | HIGH | 7.2 | 2.3% | Dec 24, 2025 | Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload wi... |
| CVE-2025-68915 | MEDIUM | 4.8 | 0.2% | Dec 24, 2025 | Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/loginbanner_w.cgi XSS via a crafted banner. |
| CVE-2025-68914 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/login.cgi username SQL Injection. For example, an attacker ... |
| CVE-2025-3232 | HIGH | 8.7 | 0.5% | Dec 24, 2025 | A remote unauthenticated attacker may be able to bypass authentication by utilizing a specific API route to execute arb... |
| CVE-2025-36154 | MEDIUM | 6.2 | 0.1% | Dec 24, 2025 | IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be ... |
| CVE-2025-2515 | HIGH | 7.2 | 0.2% | Dec 24, 2025 | A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS. This flaw allows a user wi... |
| CVE-2025-68750 | — | — | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: potential integer overflow in usbg_make_tpg() ... |
| CVE-2025-43876 | HIGH | 8.7 | 0.3% | Dec 24, 2025 | Under certain circumstances a successful exploitation could result in access to the device. |
| CVE-2025-43875 | HIGH | 8.7 | 0.3% | Dec 24, 2025 | Under certain circumstances a successful exploitation could result in access to the device. |
| CVE-2025-60935 | MEDIUM | 6.1 | 0.2% | Dec 24, 2025 | An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malici... |
| CVE-2025-2155 | HIGH | 8.8 | 0.3% | Dec 24, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Spect... |
| CVE-2025-2154 | MEDIUM | 5.4 | 0.1% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Echo Call C... |
| CVE-2025-5448 | — | — | — | Dec 24, 2025 | Rejected reason: This CVE id was assigned but later discarded. |
| CVE-2025-68749 | MEDIUM | 4.7 | 0.1% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix race condition when unbinding BOs ... |
| CVE-2025-68748 | HIGH | 7.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix UAF race between device unplug and... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now