2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15424 | CRITICAL | 9.8 | 0.4% | Jan 2, 2026 | A vulnerability was found in Yonyou KSOA 9.0. The affected element is an unknown function of the file /worksheet/agent_w... |
| CVE-2025-14998 | CRITICAL | 9.8 | 0.5% | Jan 2, 2026 | The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and in... |
| CVE-2025-15421 | CRITICAL | 9.8 | 0.4% | Jan 2, 2026 | A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/agent_wo... |
| CVE-2025-15420 | CRITICAL | 9.8 | 0.4% | Jan 2, 2026 | A security vulnerability has been detected in Yonyou KSOA 9.0. This affects an unknown part of the file /worksheet/agent... |
| CVE-2025-68620 | CRITICAL | 9.1 | 0.5% | Jan 1, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two featur... |
| CVE-2025-15410 | CRITICAL | 9.8 | 0.3% | Jan 1, 2026 | A vulnerability was identified in code-projects Online Guitar Store 1.0. Affected by this issue is some unknown function... |
| CVE-2025-15409 | CRITICAL | 9.8 | 0.4% | Jan 1, 2026 | A vulnerability was determined in code-projects Online Guitar Store 1.0. Affected by this vulnerability is an unknown fu... |
| CVE-2025-15408 | CRITICAL | 9.8 | 0.3% | Jan 1, 2026 | A vulnerability was found in code-projects Online Guitar Store 1.0. Affected is an unknown function of the file /admin/C... |
| CVE-2025-15407 | CRITICAL | 9.8 | 0.3% | Jan 1, 2026 | A vulnerability has been found in code-projects Online Guitar Store 1.0. This impacts an unknown function of the file /a... |
| CVE-2025-69288 | CRITICAL | 9.1 | 0.8% | Dec 31, 2025 | Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user... |
| CVE-2025-69286 | CRITICAL | 9.8 | 0.8% | Dec 31, 2025 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecu... |
| CVE-2025-34468 | CRITICAL | 9.8 | 0.7% | Dec 31, 2025 | libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a stack-based buffer overflow in address re... |
| CVE-2025-15391 | CRITICAL | 9.8 | 4.4% | Dec 31, 2025 | A weakness has been identified in D-Link DIR-806A 100CNb11. Affected is the function ssdpcgi_main of the component SSDP ... |
| CVE-2025-15114 | CRITICAL | 9.8 | 0.5% | Dec 30, 2025 | Ksenia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alar... |
| CVE-2025-15113 | CRITICAL | 9.3 | 0.4% | Dec 30, 2025 | Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that all... |
| CVE-2025-15111 | CRITICAL | 9.8 | 0.5% | Dec 30, 2025 | Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized a... |
| CVE-2025-15357 | CRITICAL | 9.8 | 3.8% | Dec 30, 2025 | A vulnerability was found in D-Link DI-7400G+ 19.12.25A1. This affects an unknown function of the file /msp_info.htm?fla... |
| CVE-2025-50343 | CRITICAL | 9.8 | 0.3% | Dec 30, 2025 | An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfie... |
| CVE-2025-15354 | CRITICAL | 9.8 | 0.3% | Dec 30, 2025 | A flaw has been found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the ... |
| CVE-2025-15353 | CRITICAL | 9.8 | 0.3% | Dec 30, 2025 | A vulnerability was detected in itsourcecode Society Management System 1.0. Impacted is the function edit_admin_query of... |
| CVE-2025-15263 | CRITICAL | 9.8 | 0.3% | Dec 30, 2025 | A weakness has been identified in BiggiDroid Simple PHP CMS 1.0. Affected is an unknown function of the file /admin/logi... |
| CVE-2025-56332 | CRITICAL | 9.1 | 0.4% | Dec 30, 2025 | Authentication Bypass in fosrl/pangolin v1.6.2 and before allows attackers to access Pangolin resource via Insecure Defa... |
| CVE-2025-68926 | CRITICAL | 9.8 | 29.0% | Dec 30, 2025 | RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC... |
| CVE-2025-66848 | CRITICAL | 9.8 | 1.0% | Dec 30, 2025 | JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier... |
| CVE-2025-52835 | CRITICAL | 9.6 | 0.2% | Dec 30, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ConoHa by GMO WING WordPress Migrator wing-migrator allows Upload a W... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now