2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68607 | MEDIUM | 6.5 | 0.2% | Dec 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hiroaki Miyashita ... |
| CVE-2025-68504 | MEDIUM | 6.5 | 0.2% | Dec 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSear... |
| CVE-2025-68503 | MEDIUM | 6.5 | 0.3% | Dec 29, 2025 | Missing Authorization vulnerability in Crocoblock JetBlog jet-blog allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2025-68502 | MEDIUM | 4.3 | 0.2% | Dec 29, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Crocoblock JetPopup jet-popup allows Exploiting Incorr... |
| CVE-2025-69205 | MEDIUM | 6.3 | 0.1% | Dec 29, 2025 | Micro Registration Utility (µURU) is a telephone self registration utility based on asterisk. In versions up to and incl... |
| CVE-2025-15204 | MEDIUM | 4.8 | 0.2% | Dec 29, 2025 | A vulnerability was determined in SohuTV CacheCloud up to 3.2.0. Affected is the function doQuartzList of the file src/m... |
| CVE-2025-69202 | MEDIUM | 6.5 | 0.3% | Dec 29, 2025 | Axios Cache Interceptor is a cache interceptor for axios. Prior to version 1.11.1, when a server calls an upstream servi... |
| CVE-2025-15203 | MEDIUM | 4.8 | 0.2% | Dec 29, 2025 | A vulnerability was found in SohuTV CacheCloud up to 3.2.0. This impacts the function index of the file src/main/java/co... |
| CVE-2025-15202 | MEDIUM | 4.8 | 0.2% | Dec 29, 2025 | A vulnerability has been found in SohuTV CacheCloud up to 3.2.0. This affects the function taskQueueList of the file src... |
| CVE-2025-14175 | MEDIUM | 6.5 | 0.3% | Dec 29, 2025 | A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling ... |
| CVE-2025-15201 | MEDIUM | 5.4 | 0.2% | Dec 29, 2025 | A flaw has been found in SohuTV CacheCloud up to 3.2.0. The impacted element is the function redirectNoPower of the file... |
| CVE-2025-15200 | MEDIUM | 4.8 | 0.2% | Dec 29, 2025 | A vulnerability was detected in SohuTV CacheCloud up to 3.2.0. The affected element is the function getExceptionStatisti... |
| CVE-2025-14728 | MEDIUM | 6.8 | 0.5% | Dec 29, 2025 | Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue clie... |
| CVE-2025-14280 | MEDIUM | 5.3 | 0.4% | Dec 29, 2025 | The PixelYourSite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2025-55064 | MEDIUM | 4.8 | 0.1% | Dec 29, 2025 | CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') |
| CVE-2025-55063 | MEDIUM | 4.8 | 0.1% | Dec 29, 2025 | CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') |
| CVE-2025-55062 | MEDIUM | 4.8 | 0.1% | Dec 29, 2025 | CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') |
| CVE-2025-55060 | MEDIUM | 6.1 | 0.1% | Dec 29, 2025 | CWE-601 URL Redirection to Untrusted Site ('Open Redirect') |
| CVE-2025-68868 | MEDIUM | 6.5 | 0.1% | Dec 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codeaffairs Wp Tex... |
| CVE-2025-53627 | MEDIUM | 5.3 | 0.2% | Dec 29, 2025 | Meshtastic is an open source mesh networking solution. The Meshtastic firmware (starting from version 2.5) introduces as... |
| CVE-2025-69206 | MEDIUM | 4.3 | 0.2% | Dec 29, 2025 | Hemmelig is a messing app with with client-side encryption and self-destructing messages. Prior to version 7.3.3, a Serv... |
| CVE-2025-68951 | MEDIUM | 6.1 | 0.2% | Dec 29, 2025 | phpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vuln... |
| CVE-2025-68893 | MEDIUM | 4.9 | 0.1% | Dec 29, 2025 | Server-Side Request Forgery (SSRF) vulnerability in HETWORKS WordPress Image shrinker wp-image-shrinker allows Server Si... |
| CVE-2025-68928 | MEDIUM | 5.4 | 0.2% | Dec 29, 2025 | Frappe CRM is an open-source customer relationship management tool. Prior to version 1.56.2, authenticated users could s... |
| CVE-2025-65442 | MEDIUM | 6.1 | 0.3% | Dec 29, 2025 | DOM-based Cross-Site Scripting (XSS) vulnerability in 201206030 novel V3.5.0 allows remote attackers to execute arbitrar... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now