2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1003 | HIGH | 8.5 | 0.2% | Feb 4, 2025 | A potential vulnerability has been identified in HP Anyware Agent for Linux which might allow for authentication bypass ... |
| CVE-2025-24958 | HIGH | 8.8 | 0.5% | Feb 3, 2025 | WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio... |
| CVE-2025-24902 | HIGH | 8.8 | 0.5% | Feb 3, 2025 | WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio... |
| CVE-2025-24901 | HIGH | 8.8 | 0.5% | Feb 3, 2025 | WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio... |
| CVE-2025-24371 | HIGH | 7.1 | 0.4% | Feb 3, 2025 | CometBFT is a distributed, Byzantine fault-tolerant, deterministic state machine replication engine. In the `blocksync` ... |
| CVE-2025-24962 | HIGH | 8.8 | 0.7% | Feb 3, 2025 | reNgine is an automated reconnaissance framework for web applications. In affected versions a user can inject commands v... |
| CVE-2025-24960 | HIGH | 8.7 | 0.5% | Feb 3, 2025 | Jellystat is a free and open source Statistics App for Jellyfin. In affected versions Jellystat is directly using a user... |
| CVE-2025-24899 | HIGH | 7.5 | 0.5% | Feb 3, 2025 | reNgine is an automated reconnaissance framework for web applications. A vulnerability was discovered in reNgine, where ... |
| CVE-2025-22918 | HIGH | 7.5 | 0.3% | Feb 3, 2025 | Polycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies. This allows for the us... |
| CVE-2025-25181 | HIGH | 7.5 | 50.4% | Feb 3, 2025 | A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to ex... |
| CVE-2025-25064 | HIGH | 8.8 | 34.4% | Feb 3, 2025 | SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10... |
| CVE-2025-24781 | HIGH | 7.1 | 0.3% | Feb 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WPJobBoar... |
| CVE-2025-24707 | HIGH | 7.1 | 0.3% | Feb 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Ga... |
| CVE-2025-24684 | HIGH | 7.1 | 0.3% | Feb 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ederson Peka Media... |
| CVE-2025-24676 | HIGH | 7.1 | 0.3% | Feb 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in umangmetatagg Cust... |
| CVE-2025-24661 | HIGH | 8.8 | 0.6% | Feb 3, 2025 | Deserialization of Untrusted Data vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking... |
| CVE-2025-24660 | HIGH | 7.1 | 0.3% | Feb 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wp.insider Simple ... |
| CVE-2025-24656 | HIGH | 7.1 | 0.3% | Feb 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Realtyna Realtyna ... |
| CVE-2025-24646 | HIGH | 7.1 | 0.3% | Feb 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icopydoc XML for A... |
| CVE-2025-24631 | HIGH | 7.1 | 0.3% | Feb 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Email A... |
| CVE-2025-24630 | HIGH | 7.1 | 0.3% | Feb 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MantraBrain Sikshy... |
| CVE-2025-24629 | HIGH | 7.1 | 0.3% | Feb 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpgear Import Exce... |
| CVE-2025-24620 | HIGH | 7.1 | 0.3% | Feb 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hkharpreetkumar1 A... |
| CVE-2025-24605 | HIGH | 7.2 | 0.6% | Feb 3, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-edi... |
| CVE-2025-24576 | HIGH | 7.1 | 0.3% | Feb 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fatcatapps Landing... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now