2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31900 | HIGH | 7.1 | 0.2% | Apr 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lexicata Lexicata ... |
| CVE-2025-31899 | HIGH | 7.1 | 0.2% | Apr 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpshopee Awesome L... |
| CVE-2025-31898 | HIGH | 7.1 | 0.2% | Apr 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dustinscarberry Me... |
| CVE-2025-31626 | HIGH | 7.1 | 0.3% | Apr 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M. Ali Saleem Supp... |
| CVE-2025-31582 | HIGH | 7.1 | 0.3% | Apr 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashish Ajani Conta... |
| CVE-2025-31573 | HIGH | 7.1 | 0.3% | Apr 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pepro Dev. Group P... |
| CVE-2025-31536 | HIGH | 7.1 | 0.3% | Apr 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moshensky CF7 Spre... |
| CVE-2025-31468 | HIGH | 7.1 | 0.3% | Apr 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scottsm WP_Identic... |
| CVE-2025-31467 | HIGH | 7.1 | 0.3% | Apr 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in miro.mannino Flick... |
| CVE-2025-31442 | HIGH | 7.1 | 0.3% | Apr 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e1tekoap42 Search ... |
| CVE-2025-31436 | HIGH | 7.1 | 0.3% | Apr 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Angelo Mandato Blu... |
| CVE-2025-31098 | HIGH | 7.5 | 0.7% | Apr 3, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-30908 | HIGH | 7.1 | 0.1% | Apr 3, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Shamalli Web Directory Free web-directory-free allows Stored XSS.This... |
| CVE-2025-30889 | HIGH | 8.8 | 0.4% | Apr 3, 2025 | Deserialization of Untrusted Data vulnerability in PickPlugins Testimonial Slider testimonial allows Object Injection.Th... |
| CVE-2025-30858 | HIGH | 7.1 | 0.3% | Apr 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software... |
| CVE-2025-30616 | HIGH | 7.1 | 0.3% | Apr 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Wood Latest ... |
| CVE-2025-30611 | HIGH | 7.1 | 0.3% | Apr 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wptobe Wptobe-sign... |
| CVE-2025-22931 | HIGH | 7.5 | 0.4% | Apr 3, 2025 | An insecure direct object reference (IDOR) in the component /assets/stafffiles of OS4ED openSIS v7.0 to v9.1 allows unau... |
| CVE-2025-2945 | HIGH | 8.8 | 39.1% | Apr 3, 2025 | Remote Code Execution security vulnerability in pgAdmin 4 (Query Tool and Cloud Deployment modules). The vulnerability... |
| CVE-2025-22004 | HIGH | 8.6 | 0.2% | Apr 3, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: atm: fix use after free in lec_send() The ->s... |
| CVE-2025-21999 | HIGH | 7.8 | 0.2% | Apr 3, 2025 | In the Linux kernel, the following vulnerability has been resolved: proc: fix UAF in proc_get_inode() Fix race between... |
| CVE-2025-3148 | HIGH | 7.8 | 0.2% | Apr 3, 2025 | A vulnerability was found in codeprojects Product Management System 1.0 and classified as problematic. This issue affect... |
| CVE-2025-3143 | HIGH | 8.8 | 0.4% | Apr 3, 2025 | A vulnerability classified as critical has been found in SourceCodester Apartment Visitor Management System 1.0. Affecte... |
| CVE-2025-3142 | HIGH | 8.8 | 0.4% | Apr 3, 2025 | A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been rated as critical. This... |
| CVE-2025-3139 | HIGH | 7.8 | 0.2% | Apr 3, 2025 | A vulnerability was found in code-projects Bus Reservation System 1.0 and classified as critical. Affected by this issue... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now