2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-70058HIGH7.4An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application dis...
CVE-2025-70045HIGH7.4An issue pertaining to CWE-295: Improper Certificate Validation was discovered in jxcore jxm master. The application dis...
CVE-2025-70044MEDIUM6.5An issue pertaining to CWE-295: Improper Certificate Validation was discovered in fofolee uTools-quickcommand 5.0.3.
CVE-2025-70043CRITICAL9.1An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application d...
CVE-2025-14905HIGH7.2A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callbac...
CVE-2025-69700HIGH7.5Tenda FH1203 V2.0.1.6 contains a stack-based buffer overflow vulnerability in the modify_add_client_prio function, which...
CVE-2025-59873MEDIUM5.9An information exposure vulnerability exists in Vulnerability in HCL Software ZIE for Web. The application transmits s...
CVE-2025-40986MEDIUM5.1Reflected Cross-Site Scripting (XSS) vulnerability in PideTuCita. This vulnerability allows an attacker to execute JavaS...
CVE-2025-40701MEDIUM5.1Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute J...
CVE-2025-41002CRITICAL9.3SQL injection vulnerability in Infoticketing. This vulnerability allows an unauthenticated attacker to retrieve, create...
CVE-2025-14339MEDIUM6.5The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for Wo...
CVE-2025-65995MEDIUM6.5When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operat...
CVE-2025-62326MEDIUM4.8HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which wo...
CVE-2025-70833CRITICAL9.4An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any u...
CVE-2025-15583MEDIUM5.4A weakness has been identified in detronetdip E-commerce 1.0.0. This affects the function get_safe_value of the file uti...
CVE-2025-15582HIGH8.1A security flaw has been discovered in detronetdip E-commerce 1.0.0. The impacted element is the function Delete/Update ...
CVE-2025-70831CRITICAL9.8A Remote Code Execution (RCE) vulnerability was found in Smanga 3.2.7 in the /php/path/rescan.php interface. The applica...
CVE-2025-69410HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69409HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69408HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69407HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69406HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-69405CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Lorem Ipsum | Books & Media Store lorem-ipsum-books-media-st...
CVE-2025-69404CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Extreme Store extremestore allows Object Injection.This issu...
CVE-2025-69403CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Bravis-Themes Bravis Addons bravis-addons allows Using ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now