2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-24587HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nks Email Subscrip...
CVE-2025-24570HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vito Peleg Atarim ...
CVE-2025-24562HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Optimal Access KBucket kbucket allows Stored XSS.This issue affects K...
CVE-2025-24561HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in awcode ReviewsTap reviewstap allows Stored XSS.This issue affects Rev...
CVE-2025-24555HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in subscriptiondna Subscription DNA subscriptiondna allows Stored XSS.Th...
CVE-2025-24362HIGH7.1In some circumstances, debug artifacts uploaded by the CodeQL Action after a failed code scanning workflow run may conta...
CVE-2025-0702HIGH8.8A vulnerability classified as critical was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. T...
CVE-2025-24359HIGH8.4ASTEVAL is an evaluator of Python expressions and statements. Prior to version 1.0.6, if an attacker can control the inp...
CVE-2025-24355HIGH7.1Updatecli is a tool used to apply file update strategies. Prior to version 0.93.0, private maven repository credentials ...
CVE-2025-23222HIGH8.4An issue was discovered in Deepin dde-api-proxy through 1.0.19 in which unprivileged users can access D-Bus services as ...
CVE-2025-0701HIGH8.8A vulnerability classified as critical has been found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf5...
CVE-2025-0700HIGH8.8A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. It has been rated as cri...
CVE-2025-22606HIGH7.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In version 4.0.0-bet...
CVE-2025-0699HIGH8.8A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. It has been declared as ...
CVE-2025-0698HIGH8.8A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. It has been classified a...
CVE-2025-22605HIGH7.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Starting in version ...
CVE-2025-23889HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tormorten FooGalle...
CVE-2025-23888HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GrandSlambert Cust...
CVE-2025-23885HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in anildhiman MJ Cont...
CVE-2025-23839HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Asif Shakeel Stick...
CVE-2025-23838HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rally Vincent Baue...
CVE-2025-23837HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in martinjuhasz One B...
CVE-2025-23737HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thobian Network-Fa...
CVE-2025-23734HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Casey Bisson Gigao...
CVE-2025-23711HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Quincy Kwende Quot...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now