2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66398 | HIGH | 8.8 | 17.9% | Jan 1, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticate... |
| CVE-2025-48769 | HIGH | 8.1 | 1.5% | Jan 1, 2026 | Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implem... |
| CVE-2025-47411 | HIGH | 8.1 | 14.8% | Jan 1, 2026 | A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apac... |
| CVE-2025-15406 | HIGH | 8.8 | 0.4% | Jan 1, 2026 | A flaw has been found in PHPGurukul Online Course Registration up to 3.1. This affects an unknown function. This manipul... |
| CVE-2025-15405 | HIGH | 8.8 | 0.2% | Jan 1, 2026 | A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function. The manipulation results... |
| CVE-2025-15404 | HIGH | 8.8 | 0.3% | Jan 1, 2026 | A security vulnerability has been detected in campcodes School File Management System 1.0. The affected element is an un... |
| CVE-2025-11157 | HIGH | 7.8 | 0.3% | Jan 1, 2026 | A high-severity remote code execution vulnerability exists in feast-dev/feast version 0.53.0, specifically in the Kubern... |
| CVE-2025-68700 | HIGH | 8.8 | 0.5% | Dec 31, 2025 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged aut... |
| CVE-2025-34469 | HIGH | 7.5 | 0.6% | Dec 31, 2025 | Cowrie versions prior to 2.9.0 contain a server-side request forgery (SSRF) vulnerability in the emulated shell implemen... |
| CVE-2025-15398 | HIGH | 8.1 | 0.5% | Dec 31, 2025 | A security vulnerability has been detected in Uasoft badaso up to 2.9.7. Affected is the function forgetPassword of the ... |
| CVE-2025-53235 | HIGH | 7.1 | 0.2% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osuthorpe Easy Soc... |
| CVE-2025-52739 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Sala allows ... |
| CVE-2025-50053 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nebelhorn Blappsta... |
| CVE-2025-47566 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomSounds allows ... |
| CVE-2025-31054 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Themefy Bloggie allows Reflected XSS.This issue affects Bloggie: from... |
| CVE-2025-30628 | HIGH | 8.5 | 0.2% | Dec 31, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Aff... |
| CVE-2025-28949 | HIGH | 8.5 | 0.2% | Dec 31, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codedraft Mediabay... |
| CVE-2025-23757 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proloy Chakroborty... |
| CVE-2025-23719 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zckevin ZhinaTwitt... |
| CVE-2025-23707 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matamko En Masse e... |
| CVE-2025-23705 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terry Zielke Zielk... |
| CVE-2025-23667 | HIGH | 7.1 | 0.1% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Christopher Church... |
| CVE-2025-15394 | HIGH | 7.2 | 0.4% | Dec 31, 2025 | A vulnerability was detected in iCMS up to 8.0.0. Affected is the function Save of the file app/config/ConfigAdmincp.php... |
| CVE-2025-15393 | HIGH | 8.8 | 0.4% | Dec 31, 2025 | A security vulnerability has been detected in Kohana KodiCMS up to 13.82.135. This impacts the function Save of the file... |
| CVE-2025-23608 | HIGH | 7.1 | 0.2% | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Omar Mohamed Moham... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now