2025 CVE Vulnerabilities
45,296 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26744 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlog... |
| CVE-2025-26743 | HIGH | 7.1 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TC.K Advance WP Qu... |
| CVE-2025-26741 | HIGH | 8.8 | 0.3% | Apr 15, 2025 | Missing Authorization vulnerability in AWEOS GmbH Email Notifications for Updates wp-update-mail-notification allows Pri... |
| CVE-2025-32943 | MEDIUM | 4.3 | 0.4% | Apr 15, 2025 | The vulnerability allows any authenticated user to leak the contents of arbitrary “.m3u8” files from the PeerTube server... |
| CVE-2025-1688 | MEDIUM | 5.5 | 0.2% | Apr 15, 2025 | Milestone Systems has discovered a security vulnerability in Milestone XProtect installer that resets system configurati... |
| CVE-2025-2083 | MEDIUM | 6.4 | 0.3% | Apr 15, 2025 | The Logo Carousel Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sliderId’ p... |
| CVE-2025-3579 | CRITICAL | 9.3 | 0.5% | Apr 15, 2025 | In versions prior to Aidex 1.7, an authenticated malicious user, taking advantage of an open registry, could execute una... |
| CVE-2025-3578 | CRITICAL | 9.3 | 0.4% | Apr 15, 2025 | A malicious, authenticated user in Aidex, versions prior to 1.7, could list credentials of other users, create or modify... |
| CVE-2025-3575 | HIGH | 8.7 | 0.4% | Apr 15, 2025 | Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive infor... |
| CVE-2025-3574 | HIGH | 8.7 | 0.4% | Apr 15, 2025 | Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive infor... |
| CVE-2025-3622 | MEDIUM | 5.5 | 0.4% | Apr 15, 2025 | A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects t... |
| CVE-2025-3576 | MEDIUM | 5.9 | 0.3% | Apr 15, 2025 | A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due... |
| CVE-2025-32993 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | Vision Helpdesk through 5.7.0 allows Time-Based Blind SQL injection via the Forgot Password (aka index.php?/home/forgot-... |
| CVE-2025-2225 | MEDIUM | 5.4 | 0.2% | Apr 15, 2025 | The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulne... |
| CVE-2025-3573 | MEDIUM | 6.1 | 0.3% | Apr 15, 2025 | Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() ... |
| CVE-2025-29984 | HIGH | 7.3 | 0.1% | Apr 15, 2025 | Dell Trusted Device, versions prior to 7.0.3.0, contain an Incorrect Default Permissions vulnerability. A low privilege... |
| CVE-2025-29983 | HIGH | 7.3 | 0.1% | Apr 15, 2025 | Dell Trusted Device, versions prior to 7.0.3.0, contain an Improper Link Resolution Before File Access ('Link Following'... |
| CVE-2025-3613 | MEDIUM | 5.1 | 0.3% | Apr 15, 2025 | A vulnerability has been found in Demtec Graphytics 5.0.7 and classified as problematic. This vulnerability affects unkn... |
| CVE-2025-3612 | MEDIUM | 5.3 | 0.4% | Apr 15, 2025 | A vulnerability, which was classified as problematic, was found in Demtec Graphytics 5.0.7. This affects an unknown part... |
| CVE-2025-3470 | MEDIUM | 4.9 | 0.3% | Apr 15, 2025 | The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the s ... |
| CVE-2025-32997 | MEDIUM | 5.3 | 0.4% | Apr 15, 2025 | In http-proxy-middleware before 2.0.9 and 3.x before 3.0.5, fixRequestBody proceeds even if bodyParser has failed. |
| CVE-2025-32996 | MEDIUM | 5.3 | 0.4% | Apr 15, 2025 | In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because "else if" is not used. |
| CVE-2025-32941 | — | — | — | Apr 15, 2025 | Rejected reason: Not used |
| CVE-2025-32940 | — | — | — | Apr 15, 2025 | Rejected reason: Not used |
| CVE-2025-32939 | — | — | — | Apr 15, 2025 | Rejected reason: Not used |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now