2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-23461HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xkollsoftware Soci...
CVE-2025-23454HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flashmaniac Nature...
CVE-2025-24001HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Ngô Thắng IT PPO Call To Actions ppo-call-to-actions allows Cross Sit...
CVE-2025-22735HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Steve Burge WordPr...
CVE-2025-22733HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auction...
CVE-2025-22719HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikAppoin...
CVE-2025-22717HIGH7.5Missing Authorization vulnerability in Joe Dolson My Tickets my-tickets allows Accessing Functionality Not Properly Cons...
CVE-2025-22716HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in taskbuilder Taskbu...
CVE-2025-22711HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thomas Maier Image...
CVE-2025-22710HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in storeapps Smart Ma...
CVE-2025-22709HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verg...
CVE-2025-22706HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iova.mihai Social ...
CVE-2025-22322HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DeluxeThemes Priva...
CVE-2025-22318HIGH7.5Missing Authorization vulnerability in enituretechnology Standard Box Sizes – for WooCommerce standard-box-sizes.This is...
CVE-2025-22311HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-23184HIGH7.5A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some...
CVE-2025-23044HIGH8.1PwnDoc is a penetration test report generator. There is no CSRF protection in pwndoc, allowing attackers to send request...
CVE-2025-24337HIGH8.4WriteFreely through 0.15.1, when MySQL is used, allows local users to discover credentials by reading config.ini.
CVE-2025-0479HIGH8.6This vulnerability exists in the CP Plus Router due to insecure handling of cookie flags used within its web interface. ...
CVE-2025-0590HIGH7.5Improper permission settings for mobile applications (com.transsion.carlcare) may lead to information leakage risk.
CVE-2025-0586HIGH7.2The a+HRD from aEnrich Technology has an Insecure Deserialization vulnerability, allowing remote attackers with database...
CVE-2025-0582HIGH7.2A vulnerability classified as critical was found in itsourcecode Farm Management System up to 1.0. This vulnerability af...
CVE-2025-0579HIGH7.3A vulnerability was found in Shiprocket Module 3/4 on OpenCart. It has been declared as critical. Affected by this vulne...
CVE-2025-21652HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ipvlan: Fix use-after-free in ipvlan_get_iflink(). ...
CVE-2025-21650HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: hns3: fixed hclge_fetch_pf_reg accesses bar sp...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now