2025 CVE Vulnerabilities
45,207 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32215 | MEDIUM | 6.5 | 0.2% | Apr 10, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Ability, Inc Accessibility Suite online-accessibility a... |
| CVE-2025-32214 | MEDIUM | 6.5 | 0.2% | Apr 10, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hive Support Hive ... |
| CVE-2025-32213 | MEDIUM | 6.5 | 0.3% | Apr 10, 2025 | Missing Authorization vulnerability in flothemesplugins Flo Forms flo-forms allows Exploiting Incorrectly Configured Acc... |
| CVE-2025-32212 | MEDIUM | 6.5 | 0.2% | Apr 10, 2025 | Missing Authorization vulnerability in Specia Theme Specia Companion specia-companion allows Exploiting Incorrectly Conf... |
| CVE-2025-32210 | MEDIUM | 6.5 | 0.3% | Apr 10, 2025 | Missing Authorization vulnerability in CreativeMindsSolutions CM Registration and Invitation Codes cm-invitation-codes a... |
| CVE-2025-32209 | MEDIUM | 6.5 | 0.4% | Apr 10, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in totalprocessing Nomupay ... |
| CVE-2025-32208 | MEDIUM | 6.5 | 0.3% | Apr 10, 2025 | Missing Authorization vulnerability in Hive Support Hive Support hive-support allows Exploiting Incorrectly Configured A... |
| CVE-2025-32199 | MEDIUM | 6.5 | 0.2% | Apr 10, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyale-vc Contact F... |
| CVE-2025-32198 | MEDIUM | 5.4 | 0.2% | Apr 10, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themefusecom Brizy... |
| CVE-2025-32139 | MEDIUM | 5.9 | 0.2% | Apr 10, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FooPlugins FooBox ... |
| CVE-2025-2719 | MEDIUM | 6.5 | 0.2% | Apr 10, 2025 | The Swatchly – WooCommerce Variation Swatches for Products (product attributes: Image swatch, Color swatches, Label swat... |
| CVE-2025-3489 | MEDIUM | 6.1 | 0.4% | Apr 10, 2025 | A vulnerability was found in Nababur Simple-User-Management-System 1.0. It has been rated as problematic. Affected by th... |
| CVE-2025-22471 | MEDIUM | 6.5 | 0.3% | Apr 10, 2025 | Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an integer overflow or wraparound vulnerability. An u... |
| CVE-2025-29989 | MEDIUM | 4.4 | 0.1% | Apr 10, 2025 | Dell Client Platform BIOS contains a Security Version Number Mutable to Older Versions vulnerability. A high privileged ... |
| CVE-2025-32387 | MEDIUM | 6.5 | 0.4% | Apr 9, 2025 | Helm is a package manager for Charts for Kubernetes. A JSON Schema file within a chart can be crafted with a deeply nest... |
| CVE-2025-32386 | MEDIUM | 6.5 | 0.4% | Apr 9, 2025 | Helm is a tool for managing Charts. A chart archive file can be crafted in a manner where it expands to be significantly... |
| CVE-2025-24375 | MEDIUM | 5 | 0.1% | Apr 9, 2025 | Charmed MySQL K8s operator is a Charmed Operator for running MySQL on Kubernetes. Before revision 221, the method for ca... |
| CVE-2025-29018 | MEDIUM | 4.8 | 0.2% | Apr 9, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability exists in the name parameter of pages_add_acc_type.php in Code Astro I... |
| CVE-2025-30657 | MEDIUM | 6.9 | 0.3% | Apr 9, 2025 | An Improper Encoding or Escaping of Output vulnerability in the Sampling Route Record Daemon (SRRD) of Juniper Networks ... |
| CVE-2025-30655 | MEDIUM | 6.8 | 0.1% | Apr 9, 2025 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Ne... |
| CVE-2025-30654 | MEDIUM | 6.8 | 0.1% | Apr 9, 2025 | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the User Interface (UI) of Juniper Networ... |
| CVE-2025-30653 | MEDIUM | 6.5 | 0.2% | Apr 9, 2025 | An Expired Pointer Dereference vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS ... |
| CVE-2025-30652 | MEDIUM | 6.8 | 0.1% | Apr 9, 2025 | An Improper Handling of Exceptional Conditions vulnerability in routing protocol daemon (rpd) of Juniper Networks Junos ... |
| CVE-2025-26888 | MEDIUM | 5.3 | 0.2% | Apr 9, 2025 | Missing Authorization vulnerability in Amir Helzer WooCommerce Multilingual & Multicurrency woocommerce-multilingual all... |
| CVE-2025-21597 | MEDIUM | 6 | 0.2% | Apr 9, 2025 | An Improper Check for Unusual or Exceptional Conditions vulnerability in routing protocol daemon (rpd) of Juniper Networ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now