2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-23634HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codehandling Youtu...
CVE-2025-23629HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Subhasis Laha Gall...
CVE-2025-23628HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NewMediaOne GeoDig...
CVE-2025-23626HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fukushima Kumihimo...
CVE-2025-23624HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alessandro Benoit ...
CVE-2025-23545HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Navnish Bhardwaj W...
CVE-2025-23544HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in heart5 StatPressCN...
CVE-2025-23541HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in edmon.parker Downl...
CVE-2025-23540HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mohsin Khan WP Fro...
CVE-2025-22768HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in JinHan Park Rocket Media Library Mime Type rocket-media-library-mime-...
CVE-2025-22264HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Patel WP Query Cre...
CVE-2025-0635HIGH7.5Denial of service condition in M-Files Server in versions before 25.1.14445.5 allows an unauthenticated user to consum...
CVE-2025-24030HIGH7.1Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway...
CVE-2025-0612HIGH7.5Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially expl...
CVE-2025-0611HIGH8.2Object corruption in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially exploit heap c...
CVE-2025-0651HIGH7.1Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation. User with a low sys...
CVE-2025-24399HIGH8.8Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats u...
CVE-2025-24398HIGH8.8Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that wou...
CVE-2025-20165HIGH7.5A vulnerability in the SIP processing subsystem of Cisco BroadWorks could allow an unauthenticated, remote attacker to h...
CVE-2025-20128HIGH7.5A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated...
CVE-2025-23809HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sunil Nanda Blue W...
CVE-2025-0638HIGH7.5The initial code parsing the manifest did not check the content of the file names yet later code assumed that it was che...
CVE-2025-23966HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ala Falaki a Gatew...
CVE-2025-23959HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Linus Lundahl Good...
CVE-2025-23949HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now