2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46452 | HIGH | 7.1 | 0.1% | Apr 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Olav Kolbu Google News allows Stored XSS. This issue affects Google N... |
| CVE-2025-46450 | HIGH | 7.1 | 0.1% | Apr 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in x000x occupancyplan occupancyplan allows Stored XSS.This issue affect... |
| CVE-2025-46449 | HIGH | 7.1 | 0.2% | Apr 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Novium WoWHead Too... |
| CVE-2025-46442 | HIGH | 7.1 | 0.1% | Apr 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Casey Johnson Loan Calculator repayment-calculator allows Stored XSS.... |
| CVE-2025-46439 | HIGH | 7.4 | 0.2% | Apr 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Vladimir Prelovac Plugin Central plugin-central allows Path Traversal... |
| CVE-2025-46435 | HIGH | 7.1 | 0.1% | Apr 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Yash Binani Time Based Greeting time-based-greeting allows Stored XSS... |
| CVE-2025-46234 | HIGH | 7.1 | 0.2% | Apr 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Habibur Rahman Raz... |
| CVE-2025-46230 | HIGH | 7.5 | 0.6% | Apr 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39408 | HIGH | 7.1 | 0.2% | Apr 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress BruteGua... |
| CVE-2025-39399 | HIGH | 7.5 | 0.6% | Apr 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39397 | HIGH | 7.1 | 0.2% | Apr 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus@hotmail.c... |
| CVE-2025-39391 | HIGH | 7.5 | 0.6% | Apr 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39387 | HIGH | 7.5 | 0.6% | Apr 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39384 | HIGH | 7.5 | 0.6% | Apr 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39383 | HIGH | 7.5 | 0.6% | Apr 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39382 | HIGH | 7.1 | 0.2% | Apr 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in danielpataki ACF: ... |
| CVE-2025-39381 | HIGH | 7.1 | 0.1% | Apr 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Kiotviet KiotViet Sync allows Stored XSS. This issue affects KiotViet... |
| CVE-2025-39379 | HIGH | 7.5 | 0.6% | Apr 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39378 | HIGH | 7.5 | 0.6% | Apr 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39377 | HIGH | 8.5 | 0.3% | Apr 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Appsero Hel... |
| CVE-2025-39360 | HIGH | 7.5 | 0.6% | Apr 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39359 | HIGH | 7.5 | 0.6% | Apr 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32921 | HIGH | 7.5 | 0.6% | Apr 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-43855 | HIGH | 8.7 | 0.3% | Apr 24, 2025 | tRPC allows users to build & consume fully typesafe APIs without schemas or code generation. In versions starting from 1... |
| CVE-2025-27820 | HIGH | 7.5 | 0.7% | Apr 24, 2025 | A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host na... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now