2025 CVE Vulnerabilities
45,207 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23452 | HIGH | 7.1 | 0.4% | Jan 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EditionGuard Editi... |
| CVE-2025-23445 | HIGH | 7.1 | 0.2% | Jan 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in scottswezey Easy Tynt easy-tynt allows Cross Site Request Forgery.Thi... |
| CVE-2025-23442 | HIGH | 7.1 | 0.2% | Jan 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in mschertel Shockingly Big IE6 Warning shockingly-big-ie6-warning allow... |
| CVE-2025-23438 | HIGH | 7.1 | 0.4% | Jan 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vincent Mimoun-Pra... |
| CVE-2025-23436 | HIGH | 7.1 | 0.2% | Jan 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in capa Wp-Scribd-List wp-scribd-list allows Stored XSS.This issue affec... |
| CVE-2025-23435 | HIGH | 7.1 | 0.2% | Jan 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in marcucci Password Protect Plugin for WordPress password-protect-plugi... |
| CVE-2025-23432 | HIGH | 7.1 | 0.4% | Jan 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlTi5 AlT Report a... |
| CVE-2025-23430 | HIGH | 7.1 | 0.2% | Jan 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Oren Yomtov Mass Custom Fields Manager mass-custom-fields-manager all... |
| CVE-2025-23429 | HIGH | 7.1 | 0.4% | Jan 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in altima-interactive... |
| CVE-2025-23426 | HIGH | 7.1 | 0.2% | Jan 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Binesh Dobhal go Social go-social allows Stored XSS.This issue affect... |
| CVE-2025-23424 | HIGH | 7.1 | 0.2% | Jan 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in bnovotny Marquee Style RSS News Ticker marquee-style-rss-news-ticker ... |
| CVE-2025-20630 | HIGH | 7.5 | 0.6% | Jan 16, 2025 | Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast... |
| CVE-2025-20621 | HIGH | 7.5 | 0.4% | Jan 16, 2025 | Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts... |
| CVE-2025-20072 | HIGH | 7.5 | 0.5% | Jan 16, 2025 | Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.... |
| CVE-2025-0473 | HIGH | 7.5 | 0.5% | Jan 16, 2025 | Vulnerability in the PMB platform that allows an attacker to persist temporary files on the server, affecting versions 4... |
| CVE-2025-0472 | HIGH | 7.5 | 0.5% | Jan 16, 2025 | Information exposure in the PMB platform affecting versions 4.2.13 and earlier. This vulnerability allows an attacker to... |
| CVE-2025-0457 | HIGH | 8.8 | 0.9% | Jan 16, 2025 | The airPASS from NetVision Information has an OS Command Injection vulnerability, allowing remote attackers with regular... |
| CVE-2025-22976 | HIGH | 7.1 | 0.2% | Jan 15, 2025 | SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a local attacker to execute arbitrary code via not filtering th... |
| CVE-2025-22964 | HIGH | 8.1 | 0.9% | Jan 15, 2025 | DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused... |
| CVE-2025-0492 | HIGH | 8.7 | 1.8% | Jan 15, 2025 | A vulnerability has been found in D-Link DIR-823X 240126/240802 and classified as critical. Affected by this vulnerabili... |
| CVE-2025-0490 | HIGH | 8.8 | 0.6% | Jan 15, 2025 | A vulnerability, which was classified as critical, has been found in Fanli2012 native-php-cms 1.0. This issue affects so... |
| CVE-2025-0489 | HIGH | 8.8 | 0.4% | Jan 15, 2025 | A vulnerability classified as critical was found in Fanli2012 native-php-cms 1.0. This vulnerability affects unknown cod... |
| CVE-2025-0488 | HIGH | 8.8 | 0.4% | Jan 15, 2025 | A vulnerability classified as critical has been found in Fanli2012 native-php-cms 1.0. This affects an unknown part of t... |
| CVE-2025-0484 | HIGH | 7.5 | 0.5% | Jan 15, 2025 | A vulnerability was found in Fanli2012 native-php-cms 1.0 and classified as critical. This issue affects some unknown pr... |
| CVE-2025-0482 | HIGH | 7.3 | 0.6% | Jan 15, 2025 | A vulnerability, which was classified as critical, was found in Fanli2012 native-php-cms 1.0. This affects an unknown pa... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now