2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15099CRITICAL9.8A vulnerability was identified in simstudioai sim up to 0.5.27. This vulnerability affects unknown code of the file apps...
CVE-2025-68942MEDIUM5.4Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text...
CVE-2025-68941MEDIUM5.3Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public res...
CVE-2025-68940MEDIUM5.3In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.
CVE-2025-68939MEDIUM5.3Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via...
CVE-2025-15098MEDIUM6.3A vulnerability was determined in YunaiV yudao-cloud up to 2025.11. This affects the function BpmHttpCallbackTrigger/Bpm...
CVE-2025-15097HIGH7.3A vulnerability was found in Alteryx Server. Affected by this issue is some unknown functionality of the file /gallery/a...
CVE-2025-15095LOW3.5A security vulnerability has been detected in postmanlabs httpbin up to 0.6.1. This affects an unknown function of the f...
CVE-2025-68938MEDIUM5.3Gitea before 1.25.2 mishandles authorization for deletion of releases.
CVE-2025-15094MEDIUM6.1A weakness has been identified in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The impacted element ...
CVE-2025-15093MEDIUM6.1A security flaw has been discovered in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The affected ele...
CVE-2025-15092CRITICAL9.8A vulnerability was identified in UTT 进取 512W up to 1.7.7-171114. Impacted is the function strcpy of the file /goform/Co...
CVE-2025-68937CRITICAL9.5Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of...
CVE-2025-15091CRITICAL9.8A vulnerability was determined in UTT 进取 512W up to 1.7.7-171114. This issue affects the function strcpy of the file /go...
CVE-2025-14913MEDIUM5.3The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unau...
CVE-2025-15090CRITICAL9.8A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This vulnerability affects the function strcpy of the file ...
CVE-2025-15089CRITICAL9.8A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. This affects the function strcpy of the file /goform/A...
CVE-2025-14820——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-14715——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-15088MEDIUM6.3A vulnerability was detected in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is the function postilService.lo...
CVE-2025-15087MEDIUM4.3A security vulnerability has been detected in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function submitOrderPa...
CVE-2025-15086MEDIUM4.3A weakness has been identified in youlaitech youlai-mall 1.0.0/2.0.0. This impacts the function getMemberByMobile of the...
CVE-2025-68936MEDIUM6.1ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.
CVE-2025-68935MEDIUM6.1ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to D...
CVE-2025-15085HIGH8.1A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of th...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now