2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-23719HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zckevin ZhinaTwitt...
CVE-2025-23707HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matamko En Masse e...
CVE-2025-23705HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terry Zielke Zielk...
CVE-2025-23667HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Christopher Church...
CVE-2025-66153MEDIUM5.4Missing Authorization vulnerability in merkulove Headinger for Elementor headinger-elementor allows Exploiting Incorrect...
CVE-2025-66152MEDIUM5.4Missing Authorization vulnerability in merkulove Criptopayer for Elementor criptopayer-elementor allows Exploiting Incor...
CVE-2025-66151MEDIUM5.4Missing Authorization vulnerability in merkulove Countdowner for Elementor countdowner-elementor allows Exploiting Incor...
CVE-2025-66150MEDIUM5.4Missing Authorization vulnerability in merkulove Appender appender allows Exploiting Incorrectly Configured Access Contr...
CVE-2025-66149MEDIUM5.4Missing Authorization vulnerability in merkulove UnGrabber ungrabber allows Exploiting Incorrectly Configured Access Con...
CVE-2025-34468CRITICAL9.8libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a stack-based buffer overflow in address re...
CVE-2025-34467MEDIUM4.3ZwiiCMS versions prior to 13.7.00 contain a denial-of-service vulnerability in multiple administrative endpoints due to ...
CVE-2025-15394HIGH7.2A vulnerability was detected in iCMS up to 8.0.0. Affected is the function Save of the file app/config/ConfigAdmincp.php...
CVE-2025-15393HIGH8.8A security vulnerability has been detected in Kohana KodiCMS up to 13.82.135. This impacts the function Save of the file...
CVE-2025-62989MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gora Tech Cooked c...
CVE-2025-59135MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eleopard Behance P...
CVE-2025-49355MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ikaes Accessibilit...
CVE-2025-49337MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in janhenckens Dashbo...
CVE-2025-23608HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Omar Mohamed Moham...
CVE-2025-15392HIGH8.8A weakness has been identified in Kohana KodiCMS up to 13.82.135. This affects the function like of the file cms/modules...
CVE-2025-15391CRITICAL9.8A weakness has been identified in D-Link DIR-806A 100CNb11. Affected is the function ssdpcgi_main of the component SSDP ...
CVE-2025-66160MEDIUM5.4Missing Authorization vulnerability in merkulove Select Graphist for Elementor Graphist for Elementor graphist-elemento...
CVE-2025-66159MEDIUM5.4Missing Authorization vulnerability in merkulove Walker for Elementor walker-elementor allows Exploiting Incorrectly Con...
CVE-2025-66158MEDIUM5.4Missing Authorization vulnerability in merkulove Gmaper for Elementor gmaper-elementor allows Exploiting Incorrectly Con...
CVE-2025-66157MEDIUM5.4Missing Authorization vulnerability in merkulove Sliper for Elementor sliper-elementor allows Exploiting Incorrectly Con...
CVE-2025-66156MEDIUM5.4Missing Authorization vulnerability in merkulove Watcher for Elementor watcher-elementor allows Exploiting Incorrectly C...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now