CVE Vulnerabilities in 2025

2,200 documented vulnerabilities published in 2025.

Other years: 2026 2024 2023 2022 2021 2020

Top Affected Vendors in 2025

All CVEs from 2025

CVE-2023-32238
5.4 medium

Vulnerability in CodexThemes TheGem (Elementor), CodexThemes TheGem (WPBakery).This issue affects TheGem (Elementor): from n/a before 5.8.1.1; TheGem (WPBakery): from n/a before 5.8.1.1.

Dec 30, 2025
CVE-2025-15284
3.7 low

Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1. Summary The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed notation (a[0]=1). This is a consistency bug; arrayLimit should apply unif

Qs Project Qs Dec 29, 2025
CVE-2025-15209
6.3 medium

A weakness has been identified in code-projects Refugee Food Management System 1.0. This affects an unknown part of the file /home/editfood.php. This manipulation of the argument a/b/c/d causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and

Fabian Refugee Food Management System Dec 29, 2025
CVE-2025-15208
7.3 high

A security flaw has been discovered in code-projects Refugee Food Management System 1.0. Affected by this issue is some unknown functionality of the file /home/editrefugee.php. The manipulation of the argument rfid results in sql injection. The attack can be launched remotely. The exploit has been r

Fabian Refugee Food Management System Dec 29, 2025
CVE-2025-68860
none

Authentication Bypass Using an Alternate Path or Channel vulnerability in Mobile Builder Mobile builder mobile-builder allows Authentication Abuse.This issue affects Mobile builder: from n/a through <= 1.4.2.

Dec 29, 2025
CVE-2025-68607
none

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hiroaki Miyashita Custom Field Template custom-field-template allows Stored XSS.This issue affects Custom Field Template: from n/a through <= 2.7.7.

Dec 29, 2025
CVE-2025-68562
9.9 critical

Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG allows Upload a Web Shell to a Web Server.This issue affects MapSVG: from n/a through 8.7.3.

Dec 29, 2025
CVE-2025-68504
none

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSearch jet-search allows DOM-Based XSS.This issue affects JetSearch: from n/a through <= 3.5.16.

Dec 29, 2025
CVE-2025-68503
none

Missing Authorization vulnerability in Crocoblock JetBlog jet-blog allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetBlog: from n/a through <= 2.4.7.

Dec 29, 2025
CVE-2025-68502
none

Authorization Bypass Through User-Controlled Key vulnerability in Crocoblock JetPopup jet-popup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetPopup: from n/a through <= 2.0.20.1.

Dec 29, 2025
CVE-2025-15207
7.3 high

A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/view_products.php. The manipulation of the argument chkId[] leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the pub

Campcodes Supplier Management System Dec 29, 2025
CVE-2025-15206
7.3 high

A flaw has been found in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /admin/add_area.php. Executing a manipulation of the argument txtAreaCode can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used

Campcodes Supplier Management System Dec 29, 2025
CVE-2025-69205
6.3 medium

Micro Registration Utility (µURU) is a telephone self registration utility based on asterisk. In versions up to and including commit 88db9a953f38a3026bcd6816d51c7f3b93c55893, an attacker can crafts a special federation name and characters treated special by asterisk can be injected into the `Dial( )

Dec 29, 2025
CVE-2025-15205
6.3 medium

A vulnerability was identified in code-projects Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /download.php. The manipulation of the argument istore_id leads to sql injection. The attack can be initiated remotely. The exploit is publicly a

Fabian Student File Management System Dec 29, 2025
CVE-2025-15204
2.4 low

A vulnerability was determined in SohuTV CacheCloud up to 3.2.0. Affected is the function doQuartzList of the file src/main/java/com/sohu/cache/web/controller/QuartzManageController.java. Executing manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The explo

Sohu Cachecloud Dec 29, 2025
CVE-2024-27480
9.8 critical

givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.

Vvveb Vvvebjs Dec 29, 2025
CVE-2024-25183
7.5 high

givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php.

Vvveb Vvvebjs Dec 29, 2025
CVE-2024-25182
9.8 critical

givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.

Vvveb Vvvebjs Dec 29, 2025
CVE-2025-69202
6.5 medium

Axios Cache Interceptor is a cache interceptor for axios. Prior to version 1.11.1, when a server calls an upstream service using different auth tokens, axios-cache-interceptor returns incorrect cached responses, leading to authorization bypass. The cache key is generated only from the URL, ignoring

Axios-Cache-Interceptor Axios Cache Interceptor Dec 29, 2025
CVE-2025-15203
2.4 low

A vulnerability was found in SohuTV CacheCloud up to 3.2.0. This impacts the function index of the file src/main/java/com/sohu/cache/web/controller/ResourceController.java. Performing manipulation results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been m

Sohu Cachecloud Dec 29, 2025
CVE-2025-15202
2.4 low

A vulnerability has been found in SohuTV CacheCloud up to 3.2.0. This affects the function taskQueueList of the file src/main/java/com/sohu/cache/web/controller/TaskController.java. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has been disclos

Sohu Cachecloud Dec 29, 2025
CVE-2025-14175
6.5 medium

A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling an adjacent attacker to intercept and decrypt SSH traffic. Exploitation may expose sensitive information and compromise confidentiality.

Tp-Link Tl-Wr820N Firmware Dec 29, 2025
CVE-2024-30855
8.8 high

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_action.php.

Dedecms Dedecms Dec 29, 2025
CVE-2024-25181
9.1 critical

A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from improper handling of user-supplied URLs in the "file_get_contents" function within the "save.php" file.

Vvveb Vvvebjs Dec 29, 2025