2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15118 | MEDIUM | 4.3 | 0.2% | Dec 28, 2025 | A security vulnerability has been detected in macrozheng mall up to 1.0.3. This vulnerability affects unknown code of th... |
| CVE-2025-15116 | MEDIUM | 4.8 | 0.4% | Dec 28, 2025 | A security flaw has been discovered in OpenCart up to 4.1.0.3. Affected by this issue is some unknown functionality of t... |
| CVE-2025-68972 | MEDIUM | 4.7 | 0.1% | Dec 27, 2025 | In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified... |
| CVE-2025-15106 | MEDIUM | 4.3 | 0.3% | Dec 27, 2025 | A weakness has been identified in getmaxun maxun up to 0.0.28. The affected element is the function router.get of the fi... |
| CVE-2025-15105 | MEDIUM | 5.9 | 0.5% | Dec 27, 2025 | A security flaw has been discovered in getmaxun maxun up to 0.0.28. Impacted is an unknown function of the file /getmaxu... |
| CVE-2025-68927 | MEDIUM | 6.1 | 0.2% | Dec 27, 2025 | Libredesk is a self-hosted customer support desk. Prior to version 0.8.6-beta, LibreDesk is vulnerable to stored HTML in... |
| CVE-2025-68697 | MEDIUM | 5.4 | 0.2% | Dec 26, 2025 | n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code ... |
| CVE-2025-61914 | MEDIUM | 5.4 | 0.2% | Dec 26, 2025 | n8n is an open source workflow automation platform. Prior to version 1.114.0, a stored Cross-Site Scripting (XSS) vulner... |
| CVE-2025-66737 | MEDIUM | 4.3 | 0.6% | Dec 26, 2025 | Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal. A remote normal privileged attacker can read arbi... |
| CVE-2025-67013 | MEDIUM | 6.5 | 0.2% | Dec 26, 2025 | The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not impleme... |
| CVE-2025-67349 | MEDIUM | 6.1 | 0.3% | Dec 26, 2025 | A cross-site scripting (XSS) vulnerability was identified in FluentCMS 1.2.3. After logging in as an admin and navigatin... |
| CVE-2025-66947 | MEDIUM | 6.5 | 0.3% | Dec 26, 2025 | SQL injection vulnerability in krishanmuraiji SMS v.1.0, within the /studentms/admin/edit-class-detail.php via the editi... |
| CVE-2025-65885 | MEDIUM | 5.1 | 0.1% | Dec 26, 2025 | An issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian Belle devices on Nokia 808 (Delight v1.8)... |
| CVE-2025-36230 | MEDIUM | 5.4 | 0.2% | Dec 26, 2025 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTM... |
| CVE-2025-36229 | MEDIUM | 4.3 | 0.2% | Dec 26, 2025 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data du... |
| CVE-2025-14687 | MEDIUM | 6.5 | 0.2% | Dec 26, 2025 | IBM Db2 Intelligence Center 1.1.0, 1.1.1, 1.1.2 could allow an authenticated user to perform unauthorized actions due to... |
| CVE-2025-59888 | MEDIUM | 6.7 | 0.2% | Dec 26, 2025 | Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution ... |
| CVE-2025-8075 | MEDIUM | 5.4 | 0.2% | Dec 26, 2025 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io... |
| CVE-2025-68946 | MEDIUM | 5.4 | 0.2% | Dec 26, 2025 | In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS. |
| CVE-2025-52599 | MEDIUM | 6.5 | 0.2% | Dec 26, 2025 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io... |
| CVE-2025-68945 | MEDIUM | 5.3 | 0.3% | Dec 26, 2025 | In Gitea before 1.21.2, an anonymous user can visit a private user's project. |
| CVE-2025-68944 | MEDIUM | 5.3 | 0.3% | Dec 26, 2025 | Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package... |
| CVE-2025-68943 | MEDIUM | 5.3 | 0.3% | Dec 26, 2025 | Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users... |
| CVE-2025-68942 | MEDIUM | 5.4 | 0.2% | Dec 26, 2025 | Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text... |
| CVE-2025-68941 | MEDIUM | 5.3 | 0.2% | Dec 26, 2025 | Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public res... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now