2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68940 | MEDIUM | 5.3 | 0.3% | Dec 26, 2025 | In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request. |
| CVE-2025-68939 | MEDIUM | 5.3 | 0.3% | Dec 26, 2025 | Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via... |
| CVE-2025-15098 | MEDIUM | 6.3 | 0.3% | Dec 26, 2025 | A vulnerability was determined in YunaiV yudao-cloud up to 2025.11. This affects the function BpmHttpCallbackTrigger/Bpm... |
| CVE-2025-68938 | MEDIUM | 5.3 | 0.3% | Dec 26, 2025 | Gitea before 1.25.2 mishandles authorization for deletion of releases. |
| CVE-2025-15094 | MEDIUM | 6.1 | 0.4% | Dec 26, 2025 | A weakness has been identified in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The impacted element ... |
| CVE-2025-15093 | MEDIUM | 6.1 | 0.4% | Dec 26, 2025 | A security flaw has been discovered in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The affected ele... |
| CVE-2025-14913 | MEDIUM | 5.3 | 0.3% | Dec 26, 2025 | The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unau... |
| CVE-2025-15088 | MEDIUM | 6.3 | 0.2% | Dec 25, 2025 | A vulnerability was detected in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is the function postilService.lo... |
| CVE-2025-15087 | MEDIUM | 4.3 | 0.2% | Dec 25, 2025 | A security vulnerability has been detected in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function submitOrderPa... |
| CVE-2025-15086 | MEDIUM | 4.3 | 0.3% | Dec 25, 2025 | A weakness has been identified in youlaitech youlai-mall 1.0.0/2.0.0. This impacts the function getMemberByMobile of the... |
| CVE-2025-68936 | MEDIUM | 6.1 | 0.2% | Dec 25, 2025 | ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer. |
| CVE-2025-68935 | MEDIUM | 6.1 | 0.2% | Dec 25, 2025 | ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to D... |
| CVE-2025-15083 | MEDIUM | 4.6 | 0.2% | Dec 25, 2025 | A vulnerability was determined in TOZED ZLT M30s up to 1.47. The affected element is an unknown function of the componen... |
| CVE-2025-15081 | MEDIUM | 6.3 | 2.3% | Dec 25, 2025 | A vulnerability has been found in JD Cloud BE6500 4.4.1.r4308. This issue affects the function sub_4780 of the file /jdc... |
| CVE-2025-66443 | MEDIUM | 5.3 | 0.3% | Dec 25, 2025 | Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improp... |
| CVE-2025-49088 | MEDIUM | 5.9 | 0.3% | Dec 25, 2025 | Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join... |
| CVE-2025-68919 | MEDIUM | 5.6 | 0.1% | Dec 24, 2025 | Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when ... |
| CVE-2025-68917 | MEDIUM | 6.4 | 0.2% | Dec 24, 2025 | ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer. |
| CVE-2025-68915 | MEDIUM | 4.8 | 0.2% | Dec 24, 2025 | Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/loginbanner_w.cgi XSS via a crafted banner. |
| CVE-2025-68914 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/login.cgi username SQL Injection. For example, an attacker ... |
| CVE-2025-36154 | MEDIUM | 6.2 | 0.1% | Dec 24, 2025 | IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be ... |
| CVE-2025-60935 | MEDIUM | 6.1 | 0.2% | Dec 24, 2025 | An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malici... |
| CVE-2025-2154 | MEDIUM | 5.4 | 0.1% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Echo Call C... |
| CVE-2025-68749 | MEDIUM | 4.7 | 0.1% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix race condition when unbinding BOs ... |
| CVE-2025-68606 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPXPO PostX ultimate-post al... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now