2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15218 | HIGH | 8.8 | 2.9% | Dec 30, 2025 | A weakness has been identified in Tenda AC10U 15.03.06.48/15.03.06.49. Affected by this vulnerability is the function fr... |
| CVE-2025-15217 | HIGH | 8.8 | 0.6% | Dec 30, 2025 | A security flaw has been discovered in Tenda AC23 16.03.07.52. Affected is the function formSetPPTPUserList of the compo... |
| CVE-2025-15216 | HIGH | 8.8 | 0.6% | Dec 30, 2025 | A vulnerability was identified in Tenda AC23 16.03.07.52. This impacts the function fromSetIpMacBind of the file /goform... |
| CVE-2025-15215 | HIGH | 8.8 | 0.6% | Dec 30, 2025 | A vulnerability was determined in Tenda AC10U 15.03.06.48/15.03.06.49. This affects the function formSetPPTPUserList of ... |
| CVE-2025-69235 | HIGH | 7.5 | 0.1% | Dec 30, 2025 | Whale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment. |
| CVE-2025-69217 | HIGH | 7.7 | 0.4% | Dec 30, 2025 | coturn is a free open source implementation of TURN and STUN Server. Versions 4.6.2r5 through 4.7.0-r4 have a bad random... |
| CVE-2025-68036 | HIGH | 7.5 | 0.2% | Dec 30, 2025 | Missing Authorization vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Accessing Functionality Not Properly... |
| CVE-2025-23554 | HIGH | 7.1 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jakub Glos Off Pag... |
| CVE-2025-23550 | HIGH | 7.1 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kemal YAZICI Produ... |
| CVE-2025-23469 | HIGH | 7.1 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sleekplan Sleekpla... |
| CVE-2025-23458 | HIGH | 7.1 | 0.1% | Dec 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rakessh Ads24 Lite... |
| CVE-2025-15205 | HIGH | 8.8 | 0.3% | Dec 29, 2025 | A vulnerability was identified in code-projects Student File Management System 1.0. Affected by this vulnerability is an... |
| CVE-2025-68431 | HIGH | 7.1 | 0.3% | Dec 29, 2025 | libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the ... |
| CVE-2025-67255 | HIGH | 8.8 | 0.9% | Dec 29, 2025 | In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to ... |
| CVE-2025-67254 | HIGH | 7.5 | 1.7% | Dec 29, 2025 | NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Directory Traversal in /admin/coreconfigsnapshots.php. |
| CVE-2025-15199 | HIGH | 8.8 | 0.2% | Dec 29, 2025 | A security vulnerability has been detected in code-projects College Notes Uploading System 1.0. Impacted is an unknown f... |
| CVE-2025-13592 | HIGH | 7.2 | 0.8% | Dec 29, 2025 | The Advanced Ads plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.14 vi... |
| CVE-2025-68861 | HIGH | 7.1 | 0.2% | Dec 29, 2025 | Missing Authorization vulnerability in pluginoptimizer Plugin Optimizer plugin-optimizer allows Exploiting Incorrectly C... |
| CVE-2025-66877 | HIGH | 7.5 | 0.3% | Dec 29, 2025 | Buffer overflow vulnerability in function dcputchar in decompile.c in libming 0.4.8. |
| CVE-2025-55061 | HIGH | 8.8 | 0.3% | Dec 29, 2025 | CWE-434 Unrestricted Upload of File with Dangerous Type |
| CVE-2025-68870 | HIGH | 7.5 | 0.3% | Dec 29, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-66869 | HIGH | 7.5 | 0.3% | Dec 29, 2025 | Buffer overflow vulnerability in function strcat in asan_interceptors.cpp in libming 0.4.8. |
| CVE-2025-66866 | HIGH | 7.5 | 0.3% | Dec 29, 2025 | An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial... |
| CVE-2025-66865 | HIGH | 7.5 | 0.3% | Dec 29, 2025 | An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause ... |
| CVE-2025-66864 | HIGH | 7.5 | 0.2% | Dec 29, 2025 | An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now