2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23634 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codehandling Youtu... |
| CVE-2025-23629 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Subhasis Laha Gall... |
| CVE-2025-23628 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NewMediaOne GeoDig... |
| CVE-2025-23626 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fukushima Kumihimo... |
| CVE-2025-23624 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alessandro Benoit ... |
| CVE-2025-23545 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Navnish Bhardwaj W... |
| CVE-2025-23544 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in heart5 StatPressCN... |
| CVE-2025-23541 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in edmon.parker Downl... |
| CVE-2025-23540 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mohsin Khan WP Fro... |
| CVE-2025-22768 | HIGH | 7.1 | 0.1% | Jan 23, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in JinHan Park Rocket Media Library Mime Type rocket-media-library-mime-... |
| CVE-2025-22264 | HIGH | 7.1 | 0.2% | Jan 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Patel WP Query Cre... |
| CVE-2025-0635 | HIGH | 7.5 | 0.5% | Jan 23, 2025 | Denial of service condition in M-Files Server in versions before 25.1.14445.5 allows an unauthenticated user to consum... |
| CVE-2025-24030 | HIGH | 7.1 | 0.4% | Jan 23, 2025 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway... |
| CVE-2025-0612 | HIGH | 7.5 | 0.4% | Jan 22, 2025 | Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially expl... |
| CVE-2025-0611 | HIGH | 8.2 | 0.3% | Jan 22, 2025 | Object corruption in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially exploit heap c... |
| CVE-2025-0651 | HIGH | 7.1 | 0.3% | Jan 22, 2025 | Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation. User with a low sys... |
| CVE-2025-24399 | HIGH | 8.8 | 0.5% | Jan 22, 2025 | Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats u... |
| CVE-2025-24398 | HIGH | 8.8 | 0.3% | Jan 22, 2025 | Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that wou... |
| CVE-2025-20165 | HIGH | 7.5 | 0.8% | Jan 22, 2025 | A vulnerability in the SIP processing subsystem of Cisco BroadWorks could allow an unauthenticated, remote attacker to h... |
| CVE-2025-20128 | HIGH | 7.5 | 1.5% | Jan 22, 2025 | A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated... |
| CVE-2025-23809 | HIGH | 7.1 | 0.3% | Jan 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sunil Nanda Blue W... |
| CVE-2025-0638 | HIGH | 7.5 | 0.5% | Jan 22, 2025 | The initial code parsing the manifest did not check the content of the file names yet later code assumed that it was che... |
| CVE-2025-23966 | HIGH | 7.1 | 0.3% | Jan 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ala Falaki a Gatew... |
| CVE-2025-23959 | HIGH | 7.1 | 0.3% | Jan 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Linus Lundahl Good... |
| CVE-2025-23949 | HIGH | 8.1 | 0.9% | Jan 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now