2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46225 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Post in pa... |
| CVE-2025-3518 | MEDIUM | 4.3 | 0.2% | Apr 22, 2025 | It technically possible for a user to upload a file to a conversation despite the file upload functionality being disabl... |
| CVE-2025-3814 | MEDIUM | 6.4 | 0.3% | Apr 22, 2025 | The Tax Switch for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class-name’ pa... |
| CVE-2025-2839 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | The WP Import Export Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpiePreviewData’ fu... |
| CVE-2025-2300 | MEDIUM | 5.5 | 0.1% | Apr 22, 2025 | Hitachi Ops Center Common Services within Hitachi Ops Center OVA contains an information exposure vulnerability. This is... |
| CVE-2025-3577 | MEDIUM | 4.9 | 9.0% | Apr 22, 2025 | **UNSUPPORTED WHEN ASSIGNED** A path traversal vulnerability in the web management interface of the Zyxel AMG1302-T10B f... |
| CVE-2025-1732 | MEDIUM | 6.7 | 0.2% | Apr 22, 2025 | An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware vers... |
| CVE-2025-3855 | MEDIUM | 5.3 | 0.4% | Apr 22, 2025 | A vulnerability was found in CodeCanyon RISE Ultimate Project Manager 3.8.2 and classified as problematic. Affected by t... |
| CVE-2025-3849 | MEDIUM | 6.5 | 0.3% | Apr 22, 2025 | A vulnerability classified as problematic was found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This vulnerability affects... |
| CVE-2025-2987 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated... |
| CVE-2025-3843 | MEDIUM | 6.5 | 0.3% | Apr 21, 2025 | A vulnerability was found in panhainan DS-Java 1.0. It has been classified as problematic. Affected is an unknown functi... |
| CVE-2025-32955 | MEDIUM | 6 | 0.2% | Apr 21, 2025 | Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Versions from 0.12.0 to befor... |
| CVE-2025-28103 | MEDIUM | 6.4 | 0.2% | Apr 21, 2025 | Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request. |
| CVE-2025-28102 | MEDIUM | 6.1 | 0.2% | Apr 21, 2025 | A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML... |
| CVE-2025-28099 | MEDIUM | 4.3 | 0.3% | Apr 21, 2025 | opencms V2.3 is vulnerable to Arbitrary file read in src/main/webapp/view/admin/document/dataPage.jsp, |
| CVE-2025-32793 | MEDIUM | 4 | 0.1% | Apr 21, 2025 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1... |
| CVE-2025-28367 | MEDIUM | 6.5 | 2.1% | Apr 21, 2025 | mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. A... |
| CVE-2025-28121 | MEDIUM | 6.1 | 0.7% | Apr 21, 2025 | code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" p... |
| CVE-2025-3838 | MEDIUM | 6.1 | 0.1% | Apr 21, 2025 | An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for inst... |
| CVE-2025-3837 | MEDIUM | 6.1 | 0.3% | Apr 21, 2025 | An improper input validation vulnerability is identified in the End of Life (EOL) OVA based connect component which is d... |
| CVE-2025-43970 | MEDIUM | 5.3 | 0.4% | Apr 21, 2025 | An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by... |
| CVE-2025-43955 | MEDIUM | 6.8 | 0.3% | Apr 20, 2025 | TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expr... |
| CVE-2025-43954 | MEDIUM | 6.1 | 0.2% | Apr 20, 2025 | QMarkdown (aka quasar-ui-qmarkdown) before 2.0.5 allows XSS via headers even when when no-html is set. |
| CVE-2025-3826 | MEDIUM | 4.1 | 0.3% | Apr 20, 2025 | A vulnerability, which was classified as problematic, was found in SourceCodester Web-based Pharmacy Product Management ... |
| CVE-2025-3825 | MEDIUM | 4.1 | 0.3% | Apr 20, 2025 | A vulnerability, which was classified as problematic, has been found in SourceCodester Web-based Pharmacy Product Manage... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now