2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-22767HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Global Payments Gl...
CVE-2025-22575HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendyourweb SUPE...
CVE-2025-22566HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendyourweb ULTI...
CVE-2025-22501HIGH7.1Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Improve My City Improve M...
CVE-2025-22360HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in promact WP Azure o...
CVE-2025-22356HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stencies Stencies ...
CVE-2025-2863HIGH7.8Cross-site request forgery (CSRF) vulnerability in the web application of saTECH BCU firmware version 2.1.3, which could...
CVE-2025-2862HIGH7.5SaTECH BCU, in its firmware version 2.1.3, performs weak password encryption. This allows an attacker with access to the...
CVE-2025-2861HIGH7.5SaTECH BCU in its firmware version 2.1.3 uses the HTTP protocol. The use of the HTTP protocol for web browsing has the p...
CVE-2025-2858HIGH8.8Privilege escalation vulnerability in the saTECH BCU firmware version 2.1.3. An attacker with access to the CLI of the d...
CVE-2025-28221HIGH7.5Tenda W6_S v1.0.0.4_510 has a Buffer Overflow vulnerability in the set_local_time function, which allows remote attacker...
CVE-2025-28220HIGH7.5Tenda W6_S v1.0.0.4_510 has a Buffer Overflow vulnerability in the setcfm function, which allows remote attackers to cau...
CVE-2025-2908HIGH8.5The exposure of credentials in the call forwarding configuration module in MeetMe products in versions prior to 2024-09 ...
CVE-2025-31466HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Falcon Solutions D...
CVE-2025-31460HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in danielmuldernl OmniLeads Scripts and Tags Manager omnileads-scripts-a...
CVE-2025-31459HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in PasqualePuzio Login Alert login-alert allows Stored XSS.This issue af...
CVE-2025-31458HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in forsgren Video Embedder video-embedder allows Stored XSS.This issue a...
CVE-2025-31449HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in EricH The Visitor Counter the-visitor-counter allows Stored XSS.This ...
CVE-2025-31444HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in youtag ShowTime Slideshow showtime-slideshow allows Stored XSS.This i...
CVE-2025-31443HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Krzysztof Furtak KK I Like It kk-i-like-it allows Stored XSS.This iss...
CVE-2025-31440HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Team Terms of Use terms-of-use-2 allows Stored XSS.This is...
CVE-2025-31435HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Efficient Scripts Microblog Poster microblog-poster allows Stored XSS...
CVE-2025-31432HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-2815HIGH8.8The Administrator Z plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e...
CVE-2025-31102HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel hostel ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now