2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32959 | MEDIUM | 6.5 | 0.4% | Apr 22, 2025 | CUBA Platform is a high level framework for enterprise applications development. Prior to version 7.2.23, the local file... |
| CVE-2025-32952 | MEDIUM | 6.5 | 0.6% | Apr 22, 2025 | Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to ... |
| CVE-2025-32951 | MEDIUM | 5.4 | 0.3% | Apr 22, 2025 | Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to ... |
| CVE-2025-32950 | MEDIUM | 6.5 | 0.6% | Apr 22, 2025 | Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to ... |
| CVE-2025-32788 | MEDIUM | 4.3 | 0.2% | Apr 22, 2025 | OctoPrint provides a web interface for controlling consumer 3D printers. In versions up to and including 1.10.3, OctoPri... |
| CVE-2025-28031 | MEDIUM | 6.5 | 0.2% | Apr 22, 2025 | TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a hardcoded password for the telnet service in product.... |
| CVE-2025-1951 | MEDIUM | 6.7 | 0.2% | Apr 22, 2025 | IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute comman... |
| CVE-2025-23175 | MEDIUM | 6.1 | 0.2% | Apr 22, 2025 | Multiple XSS (CWE-79) |
| CVE-2025-3458 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ocean_gallery_id’ parameter i... |
| CVE-2025-3457 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'oceanwp_icon' shortc... |
| CVE-2025-46254 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Vi... |
| CVE-2025-46253 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ataur R GutenKit g... |
| CVE-2025-46250 | MEDIUM | 4.8 | 0.2% | Apr 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VPSUF... |
| CVE-2025-46242 | MEDIUM | 4.9 | 0.3% | Apr 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Watu Quiz watu... |
| CVE-2025-46240 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Simple ... |
| CVE-2025-46239 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Theme S... |
| CVE-2025-46238 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rbaer List Last Ch... |
| CVE-2025-46237 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre L... |
| CVE-2025-46236 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Software LLC ... |
| CVE-2025-46235 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT B... |
| CVE-2025-46233 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sirv CDN and Image... |
| CVE-2025-46229 | MEDIUM | 4.8 | 0.2% | Apr 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Israpil Textmetric... |
| CVE-2025-46228 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event p... |
| CVE-2025-46227 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brecht Custom Rela... |
| CVE-2025-46226 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ferranfg MPL-Publi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now