2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23574 | HIGH | 7.1 | 0.3% | Jan 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jonathan Lau CubeP... |
| CVE-2025-23531 | HIGH | 7.1 | 0.3% | Jan 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in davidfcarr RSVPMak... |
| CVE-2025-24685 | HIGH | 8.1 | 0.6% | Jan 27, 2025 | Path Traversal: '.../...//' vulnerability in Ihor Kit Morkva UA Shipping morkva-ua-shipping allows PHP Local File Inclus... |
| CVE-2025-23792 | HIGH | 7.1 | 0.2% | Jan 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Busters Passwor... |
| CVE-2025-23457 | HIGH | 7.1 | 0.2% | Jan 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shipdeoplugin Ship... |
| CVE-2025-22513 | HIGH | 7.1 | 0.2% | Jan 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Phillips Simp... |
| CVE-2025-0722 | HIGH | 7.2 | 0.6% | Jan 27, 2025 | A vulnerability classified as critical was found in needyamin image_gallery 1.0. This vulnerability affects unknown code... |
| CVE-2025-24858 | HIGH | 8.3 | 0.5% | Jan 26, 2025 | Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server... |
| CVE-2025-0543 | HIGH | 8.5 | 0.1% | Jan 25, 2025 | Local privilege escalation in G DATA Security Client due to incorrect assignment of privileges to directories. This vuln... |
| CVE-2025-0542 | HIGH | 7.8 | 0.2% | Jan 25, 2025 | Local privilege escalation due to incorrect assignment of privileges of temporary files in the update mechanism of G DAT... |
| CVE-2025-0682 | HIGH | 8.8 | 0.6% | Jan 25, 2025 | The ThemeREX Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.3... |
| CVE-2025-0411 | HIGH | 7 | 67.1% | Jan 25, 2025 | 7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web pro... |
| CVE-2025-0707 | HIGH | 8.5 | 0.2% | Jan 24, 2025 | A vulnerability was found in Rise Group Rise Mode Temp CPU 2.1. It has been classified as critical. This affects an unkn... |
| CVE-2025-24756 | HIGH | 7.1 | 0.2% | Jan 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in mgplugin Roi Calculator roi-calculator allows Stored XSS.This issue a... |
| CVE-2025-24753 | HIGH | 8.8 | 0.4% | Jan 24, 2025 | Missing Authorization vulnerability in StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks allows Exploiting Inc... |
| CVE-2025-24728 | HIGH | 8.5 | 0.5% | Jan 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yannick Lefebvre B... |
| CVE-2025-24717 | HIGH | 8.8 | 0.2% | Jan 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Modal Window modal-window allows Cross Site Request Forge... |
| CVE-2025-24683 | HIGH | 7.6 | 0.6% | Jan 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Chill RSVP and ... |
| CVE-2025-24672 | HIGH | 8.5 | 0.4% | Jan 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in codepeople Form Bu... |
| CVE-2025-24669 | HIGH | 8.5 | 0.4% | Jan 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in serpednet SERPed.n... |
| CVE-2025-24663 | HIGH | 7.6 | 0.6% | Jan 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mra13 Simple Downl... |
| CVE-2025-24659 | HIGH | 7.6 | 0.9% | Jan 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada WPDM – Pr... |
| CVE-2025-24636 | HIGH | 7.1 | 0.2% | Jan 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Rick Laymance MachForm Shortcode machform-shortcode allows Stored XSS... |
| CVE-2025-24618 | HIGH | 8.8 | 0.5% | Jan 24, 2025 | Missing Authorization vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-ele... |
| CVE-2025-24591 | HIGH | 8.8 | 0.5% | Jan 24, 2025 | Missing Authorization vulnerability in Ninja Team GDPR CCPA Compliance Support ninja-gdpr-compliance allows Exploiting I... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now