2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15099 | CRITICAL | 9.8 | 0.7% | Dec 26, 2025 | A vulnerability was identified in simstudioai sim up to 0.5.27. This vulnerability affects unknown code of the file apps... |
| CVE-2025-68942 | MEDIUM | 5.4 | 0.2% | Dec 26, 2025 | Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text... |
| CVE-2025-68941 | MEDIUM | 5.3 | 0.2% | Dec 26, 2025 | Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public res... |
| CVE-2025-68940 | MEDIUM | 5.3 | 0.3% | Dec 26, 2025 | In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request. |
| CVE-2025-68939 | MEDIUM | 5.3 | 0.3% | Dec 26, 2025 | Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via... |
| CVE-2025-15098 | MEDIUM | 6.3 | 0.3% | Dec 26, 2025 | A vulnerability was determined in YunaiV yudao-cloud up to 2025.11. This affects the function BpmHttpCallbackTrigger/Bpm... |
| CVE-2025-15097 | HIGH | 7.3 | 0.5% | Dec 26, 2025 | A vulnerability was found in Alteryx Server. Affected by this issue is some unknown functionality of the file /gallery/a... |
| CVE-2025-15095 | LOW | 3.5 | 0.3% | Dec 26, 2025 | A security vulnerability has been detected in postmanlabs httpbin up to 0.6.1. This affects an unknown function of the f... |
| CVE-2025-68938 | MEDIUM | 5.3 | 0.3% | Dec 26, 2025 | Gitea before 1.25.2 mishandles authorization for deletion of releases. |
| CVE-2025-15094 | MEDIUM | 6.1 | 0.4% | Dec 26, 2025 | A weakness has been identified in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The impacted element ... |
| CVE-2025-15093 | MEDIUM | 6.1 | 0.4% | Dec 26, 2025 | A security flaw has been discovered in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The affected ele... |
| CVE-2025-15092 | CRITICAL | 9.8 | 0.8% | Dec 26, 2025 | A vulnerability was identified in UTT 进取 512W up to 1.7.7-171114. Impacted is the function strcpy of the file /goform/Co... |
| CVE-2025-68937 | CRITICAL | 9.5 | 0.5% | Dec 26, 2025 | Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of... |
| CVE-2025-15091 | CRITICAL | 9.8 | 0.8% | Dec 26, 2025 | A vulnerability was determined in UTT 进取 512W up to 1.7.7-171114. This issue affects the function strcpy of the file /go... |
| CVE-2025-14913 | MEDIUM | 5.3 | 0.3% | Dec 26, 2025 | The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unau... |
| CVE-2025-15090 | CRITICAL | 9.8 | 0.7% | Dec 25, 2025 | A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This vulnerability affects the function strcpy of the file ... |
| CVE-2025-15089 | CRITICAL | 9.8 | 0.7% | Dec 25, 2025 | A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. This affects the function strcpy of the file /goform/A... |
| CVE-2025-14820 | — | — | — | Dec 25, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-14715 | — | — | — | Dec 25, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-15088 | MEDIUM | 6.3 | 0.2% | Dec 25, 2025 | A vulnerability was detected in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is the function postilService.lo... |
| CVE-2025-15087 | MEDIUM | 4.3 | 0.2% | Dec 25, 2025 | A security vulnerability has been detected in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function submitOrderPa... |
| CVE-2025-15086 | MEDIUM | 4.3 | 0.3% | Dec 25, 2025 | A weakness has been identified in youlaitech youlai-mall 1.0.0/2.0.0. This impacts the function getMemberByMobile of the... |
| CVE-2025-68936 | MEDIUM | 6.1 | 0.2% | Dec 25, 2025 | ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer. |
| CVE-2025-68935 | MEDIUM | 6.1 | 0.2% | Dec 25, 2025 | ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to D... |
| CVE-2025-15085 | HIGH | 8.1 | 0.3% | Dec 25, 2025 | A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of th... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now