2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31446 | HIGH | 7.1 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jiangmiao WP Clean... |
| CVE-2025-31445 | HIGH | 7.1 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sed Lex Pages Orde... |
| CVE-2025-31441 | HIGH | 7.1 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in S WordPress Galler... |
| CVE-2025-31431 | HIGH | 7.1 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in conlabz GmbH WP Bo... |
| CVE-2025-31097 | HIGH | 8.1 | 0.7% | Apr 1, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-31089 | HIGH | 8.5 | 0.4% | Apr 1, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Fahad Mahmood Orde... |
| CVE-2025-31086 | HIGH | 7.1 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WBW Plugins Produc... |
| CVE-2025-31085 | HIGH | 7.1 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup... |
| CVE-2025-31082 | HIGH | 8.1 | 0.7% | Apr 1, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-31081 | HIGH | 7.1 | 0.4% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable ... |
| CVE-2025-31080 | HIGH | 7.1 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Software LLC ... |
| CVE-2025-31078 | HIGH | 7.1 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enituretechnology ... |
| CVE-2025-30913 | HIGH | 7.1 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in podpirate Access A... |
| CVE-2025-30906 | HIGH | 7.1 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lisandragetnet Plu... |
| CVE-2025-30905 | HIGH | 7.1 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Secure Cop... |
| CVE-2025-30892 | HIGH | 8.8 | 0.6% | Apr 1, 2025 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Object Injectio... |
| CVE-2025-30852 | HIGH | 7.1 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emotionalonlinesto... |
| CVE-2025-30825 | HIGH | 8.8 | 0.4% | Apr 1, 2025 | Missing Authorization vulnerability in WPClever WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce wpc-sm... |
| CVE-2025-30778 | HIGH | 7.1 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VPSUF... |
| CVE-2025-30554 | HIGH | 7.1 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Abhishek Kumar Fri... |
| CVE-2025-29070 | HIGH | 7.5 | 0.8% | Apr 1, 2025 | A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remo... |
| CVE-2025-29033 | HIGH | 7.3 | 0.5% | Apr 1, 2025 | An issue in BambooHR Build v.25.0210.170831-83b08dd allows a remote attacker to escalate privileges via the /saml/index.... |
| CVE-2025-29069 | HIGH | 7.3 | 0.4% | Apr 1, 2025 | A heap buffer overflow vulnerability has been identified in the lcms2-2.16. The vulnerability exists in the UnrollChunky... |
| CVE-2025-31137 | HIGH | 7.5 | 1.1% | Apr 1, 2025 | React Router is a multi-strategy router for React bridging the gap from React 18 to React 19. There is a vulnerability i... |
| CVE-2025-27829 | HIGH | 7.3 | 0.3% | Apr 1, 2025 | An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.35. If multicast streams are enabled on d... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now