2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13158 | CRITICAL | 9.3 | 0.4% | Dec 26, 2025 | Prototype pollution vulnerability in apidoc-core versions 0.2.0 and all subsequent versions allows remote attackers to m... |
| CVE-2025-13915 | CRITICAL | 9.8 | 8.7% | Dec 26, 2025 | IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanis... |
| CVE-2025-15099 | CRITICAL | 9.8 | 0.7% | Dec 26, 2025 | A vulnerability was identified in simstudioai sim up to 0.5.27. This vulnerability affects unknown code of the file apps... |
| CVE-2025-15092 | CRITICAL | 9.8 | 0.8% | Dec 26, 2025 | A vulnerability was identified in UTT 进取 512W up to 1.7.7-171114. Impacted is the function strcpy of the file /goform/Co... |
| CVE-2025-68937 | CRITICAL | 9.5 | 0.5% | Dec 26, 2025 | Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of... |
| CVE-2025-15091 | CRITICAL | 9.8 | 0.8% | Dec 26, 2025 | A vulnerability was determined in UTT 进取 512W up to 1.7.7-171114. This issue affects the function strcpy of the file /go... |
| CVE-2025-15090 | CRITICAL | 9.8 | 0.7% | Dec 25, 2025 | A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This vulnerability affects the function strcpy of the file ... |
| CVE-2025-15089 | CRITICAL | 9.8 | 0.7% | Dec 25, 2025 | A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. This affects the function strcpy of the file /goform/A... |
| CVE-2025-59683 | CRITICAL | 9.1 | 0.3% | Dec 25, 2025 | Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, w... |
| CVE-2025-15078 | CRITICAL | 9.8 | 0.3% | Dec 25, 2025 | A vulnerability was detected in itsourcecode Student Management System 1.0. The impacted element is an unknown function ... |
| CVE-2025-15077 | CRITICAL | 9.8 | 0.3% | Dec 25, 2025 | A security vulnerability has been detected in itsourcecode Student Management System 1.0. The affected element is an unk... |
| CVE-2025-15075 | CRITICAL | 9.8 | 0.4% | Dec 25, 2025 | A security flaw has been discovered in itsourcecode Student Management System 1.0. This issue affects some unknown proce... |
| CVE-2025-15074 | CRITICAL | 9.8 | 0.4% | Dec 25, 2025 | A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unkno... |
| CVE-2025-15073 | CRITICAL | 9.8 | 0.4% | Dec 24, 2025 | A vulnerability was determined in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of ... |
| CVE-2025-8769 | CRITICAL | 9.8 | 0.9% | Dec 24, 2025 | Telenium Online Web Application is vulnerable due to a Perl script that is called to load the login page. Due to improp... |
| CVE-2025-68745 | CRITICAL | 9.8 | 0.1% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clear cmds after chip reset Commit ... |
| CVE-2025-68741 | CRITICAL | 9.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix improper freeing of purex item ... |
| CVE-2025-68726 | CRITICAL | 9.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: crypto: aead - Fix reqsize handling Commit afddce1... |
| CVE-2025-68359 | CRITICAL | 9.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double free of qgroup record after failu... |
| CVE-2025-13773 | CRITICAL | 9.8 | 3.2% | Dec 24, 2025 | The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all ve... |
| CVE-2025-68669 | CRITICAL | 9.6 | 0.4% | Dec 23, 2025 | 5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. In versions 0.15.2... |
| CVE-2025-68667 | CRITICAL | 9.9 | 0.5% | Dec 23, 2025 | Conduit is a chat server powered by Matrix. A vulnerability that affects a number of Conduit-derived homeservers allows ... |
| CVE-2025-68665 | CRITICAL | 9.1 | 0.7% | Dec 23, 2025 | LangChain is a framework for building LLM-powered applications. Prior to @langchain/core versions 0.3.80 and 1.1.8, and ... |
| CVE-2025-15049 | CRITICAL | 9.8 | 0.3% | Dec 23, 2025 | A vulnerability was identified in code-projects Online Farm System 1.0. Affected is an unknown function of the file /add... |
| CVE-2025-15048 | CRITICAL | 9.8 | 11.3% | Dec 23, 2025 | A vulnerability was determined in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/CheckTools ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now