2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-66398HIGH8.8Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticate...
CVE-2025-48769HIGH8.1Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implem...
CVE-2025-47411HIGH8.1A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apac...
CVE-2025-15406HIGH8.8A flaw has been found in PHPGurukul Online Course Registration up to 3.1. This affects an unknown function. This manipul...
CVE-2025-15405HIGH8.8A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function. The manipulation results...
CVE-2025-15404HIGH8.8A security vulnerability has been detected in campcodes School File Management System 1.0. The affected element is an un...
CVE-2025-11157HIGH7.8A high-severity remote code execution vulnerability exists in feast-dev/feast version 0.53.0, specifically in the Kubern...
CVE-2025-68700HIGH8.8RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged aut...
CVE-2025-34469HIGH7.5Cowrie versions prior to 2.9.0 contain a server-side request forgery (SSRF) vulnerability in the emulated shell implemen...
CVE-2025-15398HIGH8.1A security vulnerability has been detected in Uasoft badaso up to 2.9.7. Affected is the function forgetPassword of the ...
CVE-2025-53235HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osuthorpe Easy Soc...
CVE-2025-52739HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Sala allows ...
CVE-2025-50053HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nebelhorn Blappsta...
CVE-2025-47566HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomSounds allows ...
CVE-2025-31054HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Themefy Bloggie allows Reflected XSS.This issue affects Bloggie: from...
CVE-2025-30628HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Aff...
CVE-2025-28949HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codedraft Mediabay...
CVE-2025-23757HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proloy Chakroborty...
CVE-2025-23719HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zckevin ZhinaTwitt...
CVE-2025-23707HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matamko En Masse e...
CVE-2025-23705HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terry Zielke Zielk...
CVE-2025-23667HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Christopher Church...
CVE-2025-15394HIGH7.2A vulnerability was detected in iCMS up to 8.0.0. Affected is the function Save of the file app/config/ConfigAdmincp.php...
CVE-2025-15393HIGH8.8A security vulnerability has been detected in Kohana KodiCMS up to 13.82.135. This impacts the function Save of the file...
CVE-2025-23608HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Omar Mohamed Moham...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now