2025 CVE Vulnerabilities

45,277 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-48880MEDIUM6.6FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, when an administrative account i...
CVE-2025-48875MEDIUM5.4FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, the system's incorrect validatio...
CVE-2025-48865CRITICAL9.1Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. Prior to version 1.6.6, Fabio allows cl...
CVE-2025-48492HIGH8.8GetSimple CMS is a content management system. In versions starting from 3.3.16 to 3.3.21, an authenticated user with acc...
CVE-2025-48489MEDIUM4.8FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to...
CVE-2025-48488MEDIUM5.4FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, deleting the file .htaccess allo...
CVE-2025-48487MEDIUM4.8FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when creating a translation of a...
CVE-2025-48486MEDIUM5.4FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the cross-site scripiting (XSS) ...
CVE-2025-48485MEDIUM5.4FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to...
CVE-2025-47697HIGH7.5Client-side enforcement of server-side security issue exists in wivia 5 all versions. If exploited, an unauthenticated a...
CVE-2025-41406MEDIUM6.1Cross-site scripting vulnerability exists in wivia 5 all versions. If exploited, when a user connects to the affected de...
CVE-2025-41385HIGH7.2An OS Command Injection issue exists in wivia 5 all versions. If this vulnerability is exploited, an arbitrary OS comman...
CVE-2025-5259MEDIUM6.4The Minimal Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in...
CVE-2025-4659MEDIUM5.3The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is v...
CVE-2025-4429MEDIUM6.1The Gearside Developer Dashboard WordPress plugin through 1.0.72 does not sanitise and escape a parameter before outputt...
CVE-2025-48889HIGH7.5Gradio is an open-source Python package that allows quick building of demos and web application for machine learning mod...
CVE-2025-48881HIGH8.3Valtimo is a platform for Business Process Automation. In versions starting from 11.0.0.RELEASE to 11.3.3.RELEASE and 12...
CVE-2025-48490MEDIUM6.6Laravel Rest Api is an API generator. Prior to version 2.13.0, a validation bypass vulnerability was discovered where mu...
CVE-2025-41235HIGH8.6Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies.
CVE-2025-48484MEDIUM5.4FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application is vulnerable to...
CVE-2025-48483MEDIUM5.4FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to...
CVE-2025-48482MEDIUM4.3FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, there is a mass assignment vulne...
CVE-2025-48481CRITICAL9.8FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an attacker with an unactivated ...
CVE-2025-48480LOW2.7FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an authorized user with the admi...
CVE-2025-48479LOW2.7FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the laravel-translation-manager ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now