2025 CVE Vulnerabilities

45,209 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-48097HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shiva WSAnalytics ...
CVE-2025-48096MEDIUM6.5Missing Authorization vulnerability in FRESHFACE Custom CSS custom-css-editor allows Exploiting Incorrectly Configured A...
CVE-2025-48095MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Mak...
CVE-2025-48093HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Calvaweb Password ...
CVE-2025-48092HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jurajpuchky Fix Mu...
CVE-2025-48091HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alexander AnyComme...
CVE-2025-48082HIGH8.8Incorrect Privilege Assignment vulnerability in Progress Planner Progress Planner progress-planner allows Privilege Esca...
CVE-2025-39534HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Somonator Terms Di...
CVE-2025-32657HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-32283HIGH8.8Deserialization of Untrusted Data vulnerability in designthemes Solar Energy solar allows Object Injection.This issue af...
CVE-2025-31634HIGH8.8Deserialization of Untrusted Data vulnerability in designthemes Insurance insurance allows Object Injection.This issue a...
CVE-2025-30944HIGH7.5Missing Authorization vulnerability in Essekia Tablesome Table Premium tablesome-premium allows Accessing Functionality ...
CVE-2025-11966MEDIUM6.4In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory n...
CVE-2025-11965HIGH7.5In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], a StaticHandler configuration for restricting access to h...
CVE-2025-8848MEDIUM5.4A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header. When a ...
CVE-2025-61035HIGH7.7The seffaflik thru 0.0.9 is vulnerable to symlink attacks due to incorrect default permissions given to the .kimlik file...
CVE-2025-56447CRITICAL9.8TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.
CVE-2025-11844MEDIUM5.4Hugging Face Smolagents version 1.20.0 contains an XPath injection vulnerability in the search_item_ctrl_f function loca...
CVE-2025-11750MEDIUM5.3In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the existence of user accounts by returning d...
CVE-2025-11411MEDIUM5.7NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RR...
CVE-2025-11086HIGH8.1The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege e...
CVE-2025-6833MEDIUM4.3The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Inse...
CVE-2025-11915MEDIUM6.9Connection desynchronization between an HTTP proxy and the model backend. The fixes were rolled out for all proxies in f...
CVE-2025-41110HIGH8.8Encrypted WiFi and SSH credentials were found in the Ghost Robotics Vision 60 v0.27.2 APK. This vulnerability allows an ...
CVE-2025-41109MEDIUM4.6Ghost Robotics Vision 60 v0.27.2 includes, among its physical interfaces, three RJ45 connectors and a USB Type-C port. T...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now