2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-48240MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Cost of ...
CVE-2025-48239MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Product ...
CVE-2025-48238HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in awcode AWcode Toolkit awcode-toolkit allows Stored XSS.This issue aff...
CVE-2025-48237MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist...
CVE-2025-48236HIGH8.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bunny.net bunny.ne...
CVE-2025-48235MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bogdan Bendziukov ...
CVE-2025-48234MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Blocks Ul...
CVE-2025-48233HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in affmngr Affiliates Manager Google reCAPTCHA Integration affiliates-ma...
CVE-2025-48232MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xpro Xpro Addons F...
CVE-2025-43714MEDIUM6.5The ChatGPT system through 2025-03-30 performs inline rendering of SVG documents (instead of, for example, rendering the...
CVE-2025-3908MEDIUM6.2The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlink...
CVE-2025-30072HIGH7.6Tiiwee X1 Alarm System TWX1HAKV2 allows Authentication Bypass by Capture-replay, leading to physical Access to the prote...
CVE-2025-4935CRITICAL9.8A vulnerability was found in SourceCodester Stock Management System 1.0 and classified as critical. This issue affects s...
CVE-2025-4934CRITICAL9.8A vulnerability has been found in PHPGurukul User Registration & Login and User Management System 3.3 and classified as ...
CVE-2025-44108MEDIUM4.8A stored Cross-Site Scripting (XSS) vulnerability exists in the administration panel of Flatpress CMS before 1.4 via the...
CVE-2025-28371MEDIUM6.5EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function. The de...
CVE-2025-4933CRITICAL9.8A vulnerability, which was classified as critical, was found in ponaravindb Hospital-Management-System 1.0. This affects...
CVE-2025-4932CRITICAL9.8A vulnerability, which was classified as critical, has been found in projectworlds Online Lawyer Management System 1.0. ...
CVE-2025-4931CRITICAL9.8A vulnerability classified as critical was found in projectworlds Online Lawyer Management System 1.0. Affected by this ...
CVE-2025-4930CRITICAL9.8A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. Affected is an unknown fu...
CVE-2025-2099HIGH7.5A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transfor...
CVE-2025-4929CRITICAL9.8A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been rated as critical. This issue affects som...
CVE-2025-4928CRITICAL9.8A vulnerability was found in projectworlds Online Lawyer Management System 1.0. It has been declared as critical. This v...
CVE-2025-4927CRITICAL9.8A vulnerability was found in PHPGurukul Online Marriage Registration System 1.0. It has been classified as critical. Thi...
CVE-2025-4926HIGH7.2A vulnerability was found in PHPGurukul Car Rental Project 1.0 and classified as critical. Affected by this issue is som...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now