2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23773 | MEDIUM | 6.5 | 0.3% | Apr 17, 2025 | Missing Authorization vulnerability in mingocommerce Delete All Posts allows Exploiting Incorrectly Configured Access Co... |
| CVE-2025-22771 | MEDIUM | 6.5 | 0.2% | Apr 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Studio Hyperset Th... |
| CVE-2025-22340 | MEDIUM | 6.5 | 0.2% | Apr 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 Data Dash... |
| CVE-2025-29015 | MEDIUM | 6.1 | 0.3% | Apr 17, 2025 | Code Astro Internet Banking System 2.0.0 is vulnerable to Cross Site Scripting (XSS) via the name parameter in /admin/pa... |
| CVE-2025-3760 | MEDIUM | 5.4 | 0.2% | Apr 17, 2025 | A stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Liferay Portal 7.2.0 th... |
| CVE-2025-3487 | MEDIUM | 5.4 | 0.2% | Apr 17, 2025 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro... |
| CVE-2025-3479 | MEDIUM | 5.3 | 0.2% | Apr 17, 2025 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Order Repl... |
| CVE-2025-3453 | MEDIUM | 5.3 | 0.3% | Apr 17, 2025 | The Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products – Restrict Content, Protect... |
| CVE-2025-26478 | MEDIUM | 6.5 | 0.1% | Apr 17, 2025 | Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker... |
| CVE-2025-29931 | MEDIUM | 6.3 | 0.4% | Apr 17, 2025 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected product does not... |
| CVE-2025-2197 | MEDIUM | 4.3 | 0.2% | Apr 17, 2025 | Browser is affected by type confusion vulnerability, successful exploitation of this vulnerability may affect service av... |
| CVE-2025-3615 | MEDIUM | 6.4 | 0.3% | Apr 17, 2025 | The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form-submission.js script in ... |
| CVE-2025-3295 | MEDIUM | 4.9 | 0.4% | Apr 17, 2025 | The WP Editor plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.9.1. T... |
| CVE-2025-43717 | MEDIUM | 5.4 | 0.3% | Apr 17, 2025 | In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and ... |
| CVE-2025-31339 | MEDIUM | 5.3 | 0.4% | Apr 17, 2025 | An unrestricted upload of file with dangerous type vulnerability in the course management function of Wisdom Master Pro ... |
| CVE-2025-31338 | MEDIUM | 6.9 | 0.4% | Apr 17, 2025 | A missing authorization vulnerability in the retrieve teacher Information function of Wisdom Master Pro versions 5.0 thr... |
| CVE-2025-43704 | MEDIUM | 4.7 | 0.1% | Apr 16, 2025 | Arctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authenticatio... |
| CVE-2025-24911 | MEDIUM | 4.9 | 0.4% | Apr 16, 2025 | Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enable... |
| CVE-2025-24910 | MEDIUM | 4.9 | 0.3% | Apr 16, 2025 | Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enable... |
| CVE-2025-24909 | MEDIUM | 4.4 | 0.2% | Apr 16, 2025 | Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed... |
| CVE-2025-24908 | MEDIUM | 6.8 | 0.4% | Apr 16, 2025 | Overview The product uses external input to construct a pathname that should be within a restricted directory, ... |
| CVE-2025-24907 | MEDIUM | 6.8 | 0.4% | Apr 16, 2025 | Overview The product uses external input to construct a pathname that should be within a restricted directory, ... |
| CVE-2025-1704 | MEDIUM | 6.5 | 0.2% | Apr 16, 2025 | ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users... |
| CVE-2025-0758 | MEDIUM | 6.1 | 0.1% | Apr 16, 2025 | Overview The product specifies permissions for a security-critical resource in a way that allows that resource to be... |
| CVE-2025-0757 | MEDIUM | 4.4 | 0.2% | Apr 16, 2025 | Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now