2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31394 | HIGH | 7.1 | 0.3% | Apr 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kailey (trepmal) M... |
| CVE-2025-31393 | HIGH | 7.1 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in vfvalent Social Bookmarking RELOADED social-bookmarking-reloaded allo... |
| CVE-2025-31392 | HIGH | 7.1 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Shameem Reza Smart Product Gallery Slider smart-product-gallery-slide... |
| CVE-2025-31391 | HIGH | 7.1 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in regen Script Compressor script-compressor allows Stored XSS.This issu... |
| CVE-2025-31390 | HIGH | 7.1 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in bdoga Social Crowd social-crowd allows Stored XSS.This issue affects ... |
| CVE-2025-31388 | HIGH | 7.1 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in doa The World the-world allows Stored XSS.This issue affects The Worl... |
| CVE-2025-31385 | HIGH | 7.1 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in intelcaprep Site Table of Contents site-table-of-contents allows Stor... |
| CVE-2025-31383 | HIGH | 7.1 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in sodena FrescoChat Live Chat flexytalk-widget allows Stored XSS.This i... |
| CVE-2025-31382 | HIGH | 7.1 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in theode Language Field language-field allows Stored XSS.This issue aff... |
| CVE-2025-31377 | HIGH | 7.5 | 0.6% | Apr 9, 2025 | Missing Authorization vulnerability in Asaquzzaman mishu Woo Product Feed For Marketing Channels woocommerce-to-google-m... |
| CVE-2025-31375 | HIGH | 7.1 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in bhoogterp Scheduled scheduled allows Stored XSS.This issue affects Sc... |
| CVE-2025-31038 | HIGH | 8.8 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Essential Marketer Essential Breadcrumbs essential-breadcrumbs allows... |
| CVE-2025-31036 | HIGH | 8.8 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WPSOLR WPSolr wpsolr-free allows Privilege Escalation.This issue affe... |
| CVE-2025-31032 | HIGH | 7.1 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Pagopar - Grupo M S.A. Pagopar – WooCommerce Gateway pagopar-woocomme... |
| CVE-2025-31026 | HIGH | 7.1 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Austin Comment Validation Reloaded comment-validation-reloaded allows... |
| CVE-2025-31023 | HIGH | 8.8 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Purab Seo Meta Tags seo-meta-tags allows Cross Site Request Forgery.T... |
| CVE-2025-32380 | HIGH | 7.5 | 0.5% | Apr 9, 2025 | The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph th... |
| CVE-2025-32374 | HIGH | 7.5 | 0.3% | Apr 9, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Possible d... |
| CVE-2025-32372 | HIGH | 7.5 | 0.3% | Apr 9, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A bypass h... |
| CVE-2025-29394 | HIGH | 8.1 | 0.5% | Apr 9, 2025 | An insecure permissions vulnerability in verydows v2.0 allows a remote attacker to execute arbitrary code by uploading a... |
| CVE-2025-29391 | HIGH | 7.2 | 0.4% | Apr 9, 2025 | horvey Library-Manager v1.0 is vulnerable to SQL Injection in Admin/Controller/BookController.class.php. |
| CVE-2025-29390 | HIGH | 8.8 | 0.4% | Apr 9, 2025 | jerryhanjj ERP 1.0 is vulnerable to SQL Injection in the set_password function in application/controllers/home.php. |
| CVE-2025-1968 | HIGH | 7.7 | 0.3% | Apr 9, 2025 | Insufficient Session Expiration vulnerability in Progress Software Corporation Sitefinity under some specific and uncomm... |
| CVE-2025-29189 | HIGH | 7.6 | 0.2% | Apr 9, 2025 | Flowise <= 2.2.3 is vulnerable to SQL Injection. via tableName parameter at Postgres_VectorStores. |
| CVE-2025-2223 | HIGH | 8.4 | 0.2% | Apr 9, 2025 | CWE-20: Improper Input Validation vulnerability exists that could cause a loss of Confidentiality, Integrity and Availab... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now