2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23461 | HIGH | 7.1 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xkollsoftware Soci... |
| CVE-2025-23454 | HIGH | 7.1 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flashmaniac Nature... |
| CVE-2025-24001 | HIGH | 7.1 | 0.1% | Jan 21, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Ngô Thắng IT PPO Call To Actions ppo-call-to-actions allows Cross Sit... |
| CVE-2025-22735 | HIGH | 7.1 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Steve Burge WordPr... |
| CVE-2025-22733 | HIGH | 7.1 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auction... |
| CVE-2025-22719 | HIGH | 7.1 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikAppoin... |
| CVE-2025-22717 | HIGH | 7.5 | 0.4% | Jan 21, 2025 | Missing Authorization vulnerability in Joe Dolson My Tickets my-tickets allows Accessing Functionality Not Properly Cons... |
| CVE-2025-22716 | HIGH | 8.8 | 0.4% | Jan 21, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in taskbuilder Taskbu... |
| CVE-2025-22711 | HIGH | 7.1 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thomas Maier Image... |
| CVE-2025-22710 | HIGH | 7.6 | 0.8% | Jan 21, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in storeapps Smart Ma... |
| CVE-2025-22709 | HIGH | 7.1 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verg... |
| CVE-2025-22706 | HIGH | 7.1 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iova.mihai Social ... |
| CVE-2025-22322 | HIGH | 7.1 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DeluxeThemes Priva... |
| CVE-2025-22318 | HIGH | 7.5 | 0.3% | Jan 21, 2025 | Missing Authorization vulnerability in enituretechnology Standard Box Sizes – for WooCommerce standard-box-sizes.This is... |
| CVE-2025-22311 | HIGH | 7.5 | 0.5% | Jan 21, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-23184 | HIGH | 7.5 | 1.9% | Jan 21, 2025 | A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some... |
| CVE-2025-23044 | HIGH | 8.1 | 0.2% | Jan 20, 2025 | PwnDoc is a penetration test report generator. There is no CSRF protection in pwndoc, allowing attackers to send request... |
| CVE-2025-24337 | HIGH | 8.4 | 0.2% | Jan 20, 2025 | WriteFreely through 0.15.1, when MySQL is used, allows local users to discover credentials by reading config.ini. |
| CVE-2025-0479 | HIGH | 8.6 | 0.4% | Jan 20, 2025 | This vulnerability exists in the CP Plus Router due to insecure handling of cookie flags used within its web interface. ... |
| CVE-2025-0590 | HIGH | 7.5 | 0.3% | Jan 20, 2025 | Improper permission settings for mobile applications (com.transsion.carlcare) may lead to information leakage risk. |
| CVE-2025-0586 | HIGH | 7.2 | 0.7% | Jan 20, 2025 | The a+HRD from aEnrich Technology has an Insecure Deserialization vulnerability, allowing remote attackers with database... |
| CVE-2025-0582 | HIGH | 7.2 | 0.7% | Jan 20, 2025 | A vulnerability classified as critical was found in itsourcecode Farm Management System up to 1.0. This vulnerability af... |
| CVE-2025-0579 | HIGH | 7.3 | 0.4% | Jan 20, 2025 | A vulnerability was found in Shiprocket Module 3/4 on OpenCart. It has been declared as critical. Affected by this vulne... |
| CVE-2025-21652 | HIGH | 7.8 | 0.2% | Jan 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: ipvlan: Fix use-after-free in ipvlan_get_iflink(). ... |
| CVE-2025-21650 | HIGH | 7.8 | 0.2% | Jan 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: hns3: fixed hclge_fetch_pf_reg accesses bar sp... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now