2025 CVE Vulnerabilities
45,158 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53463 | MEDIUM | 6.5 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Mega... |
| CVE-2025-53462 | MEDIUM | 5.9 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SAPO SAPO Feed sap... |
| CVE-2025-53461 | MEDIUM | 4.4 | 0.2% | Sep 22, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Binsaifullah Beaf image-compare-block allows Server Side Request For... |
| CVE-2025-53460 | MEDIUM | 5.9 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Affili... |
| CVE-2025-53458 | MEDIUM | 5.9 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in davaxi Goracash go... |
| CVE-2025-53457 | MEDIUM | 4.4 | 0.3% | Sep 22, 2025 | Server-Side Request Forgery (SSRF) vulnerability in activewebsight SEO Backlink Monitor seo-backlink-monitor allows Serv... |
| CVE-2025-53456 | MEDIUM | 4.3 | 0.2% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in activewebsight SEO Backlink Monitor seo-backlink-monitor allows Cross... |
| CVE-2025-53455 | MEDIUM | 5.9 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CashBill CashBill.... |
| CVE-2025-53454 | MEDIUM | 6.5 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rustaurius Ultimat... |
| CVE-2025-53452 | MEDIUM | 4.3 | 0.3% | Sep 22, 2025 | Missing Authorization vulnerability in Barry Event Rocket allows Exploiting Incorrectly Configured Access Control Securi... |
| CVE-2025-53451 | MEDIUM | 5.4 | 0.2% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in mihdan Mihdan: No External Links mihdan-no-external-links allows Cros... |
| CVE-2025-52367 | MEDIUM | 5.4 | 4.3% | Sep 22, 2025 | Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the... |
| CVE-2025-36064 | MEDIUM | 5.9 | 0.5% | Sep 22, 2025 | IBM Sterling Connect:Express for Microsoft Windows 3.1.0.0 through 3.1.0.22 uses an inadequate account lockout setting t... |
| CVE-2025-59418 | MEDIUM | 5.5 | 0.2% | Sep 22, 2025 | BunnyPad is a note taking software. Prior to version 11.0.27000.0915, opening files greater than or equal to 20MB causes... |
| CVE-2025-57438 | MEDIUM | 6.8 | 0.3% | Sep 22, 2025 | The 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intend... |
| CVE-2025-55886 | MEDIUM | 6.5 | 0.3% | Sep 22, 2025 | An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the `fe_uid` paramete... |
| CVE-2025-55885 | MEDIUM | 6.3 | 0.4% | Sep 22, 2025 | SQL Injection vulnerability in Alpes Recherche et Developpement ARD GEC en Lign before v.2025-04-23 allows a remote atta... |
| CVE-2025-59413 | MEDIUM | 6.5 | 0.4% | Sep 22, 2025 | CubeCart is an ecommerce software solution. Prior to version 6.5.11, a logic flaw exists in the newsletter subscription ... |
| CVE-2025-59412 | MEDIUM | 5.4 | 0.3% | Sep 22, 2025 | CubeCart is an ecommerce software solution. Prior to version 6.5.11, a vulnerability exists in the product reviews featu... |
| CVE-2025-59411 | MEDIUM | 5.4 | 0.3% | Sep 22, 2025 | CubeCart is an ecommerce software solution. Prior to version 6.5.11, the contact form’s Enquiry field accepts raw HTML a... |
| CVE-2025-43807 | MEDIUM | 5.4 | 0.2% | Sep 22, 2025 | Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0 through 7.4.3.112, a... |
| CVE-2025-57682 | MEDIUM | 6.5 | 0.6% | Sep 22, 2025 | Directory Traversal vulnerability in Papermark 0.20.0 and prior allows authenticated attackers to retrieve arbitrary fil... |
| CVE-2025-57433 | MEDIUM | 6.5 | 0.3% | Sep 22, 2025 | The 2wcom IP-4c 2.15.5 device's web interface includes an information disclosure vulnerability. By sending a crafted POS... |
| CVE-2025-36037 | MEDIUM | 5.4 | 0.2% | Sep 22, 2025 | IBM webMethods Integration 10.15 and 11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authe... |
| CVE-2025-56075 | MEDIUM | 5.4 | 0.2% | Sep 22, 2025 | A SQL Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now