2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23622 | HIGH | 7.1 | 0.2% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sabuj Kundu CBX Ac... |
| CVE-2025-23621 | HIGH | 7.1 | 0.2% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in algothemes Causes ... |
| CVE-2025-23522 | HIGH | 7.1 | 0.2% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matthew Haines-You... |
| CVE-2025-23427 | HIGH | 7.1 | 0.2% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Anderson / T... |
| CVE-2025-23422 | HIGH | 7.5 | 0.6% | Jan 24, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in moaluko Store Locator st... |
| CVE-2025-22714 | HIGH | 7.1 | 0.2% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MDJM Mobile DJ Man... |
| CVE-2025-23012 | HIGH | 8.7 | 0.4% | Jan 23, 2025 | Fedora Repository 3.8.x includes a service account (fedoraIntCallUser) with default credentials and privileges to read r... |
| CVE-2025-23011 | HIGH | 8.8 | 0.7% | Jan 23, 2025 | Fedora Repository 3.8.1 allows path traversal when extracting uploaded archives ("Zip Slip"). A remote, authenticated at... |
| CVE-2025-24033 | HIGH | 7.5 | 0.6% | Jan 23, 2025 | @fastify/multipart is a Fastify plugin for parsing the multipart content-type. Prior to versions 8.3.1 and 9.0.3, the `s... |
| CVE-2025-22153 | HIGH | 7.9 | 0.4% | Jan 23, 2025 | RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input ... |
| CVE-2025-0650 | HIGH | 8.1 | 0.8% | Jan 23, 2025 | A flaw was found in the Open Virtual Network (OVN). Specially crafted UDP packets may bypass egress access control lists... |
| CVE-2025-23960 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in basteln3rk Save & ... |
| CVE-2025-23894 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tatsuya wp-flickr-... |
| CVE-2025-23836 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SuryaBhan Custom C... |
| CVE-2025-23835 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jmraya Legal + leg... |
| CVE-2025-23834 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RaminMT Links/Prob... |
| CVE-2025-23733 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sayoko SC Simple Z... |
| CVE-2025-23730 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flx0 FLX Dashboard... |
| CVE-2025-23729 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fures XTRA Setting... |
| CVE-2025-23727 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in antonzaroutski AZ ... |
| CVE-2025-23725 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pshikli Accessibil... |
| CVE-2025-23724 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oleksandr87 Univer... |
| CVE-2025-23723 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hdw player Plestar... |
| CVE-2025-23722 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mind3dom Mind3doM ... |
| CVE-2025-23636 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dimitar A. My Favo... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now