2025 CVE Vulnerabilities

45,207 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-23452HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EditionGuard Editi...
CVE-2025-23445HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in scottswezey Easy Tynt easy-tynt allows Cross Site Request Forgery.Thi...
CVE-2025-23442HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in mschertel Shockingly Big IE6 Warning shockingly-big-ie6-warning allow...
CVE-2025-23438HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vincent Mimoun-Pra...
CVE-2025-23436HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in capa Wp-Scribd-List wp-scribd-list allows Stored XSS.This issue affec...
CVE-2025-23435HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in marcucci Password Protect Plugin for WordPress password-protect-plugi...
CVE-2025-23432HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlTi5 AlT Report a...
CVE-2025-23430HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Oren Yomtov Mass Custom Fields Manager mass-custom-fields-manager all...
CVE-2025-23429HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in altima-interactive...
CVE-2025-23426HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Binesh Dobhal go Social go-social allows Stored XSS.This issue affect...
CVE-2025-23424HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in bnovotny Marquee Style RSS News Ticker marquee-style-rss-news-ticker ...
CVE-2025-20630HIGH7.5Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast...
CVE-2025-20621HIGH7.5Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts...
CVE-2025-20072HIGH7.5Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post....
CVE-2025-0473HIGH7.5Vulnerability in the PMB platform that allows an attacker to persist temporary files on the server, affecting versions 4...
CVE-2025-0472HIGH7.5Information exposure in the PMB platform affecting versions 4.2.13 and earlier. This vulnerability allows an attacker to...
CVE-2025-0457HIGH8.8The airPASS from NetVision Information has an OS Command Injection vulnerability, allowing remote attackers with regular...
CVE-2025-22976HIGH7.1SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a local attacker to execute arbitrary code via not filtering th...
CVE-2025-22964HIGH8.1DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused...
CVE-2025-0492HIGH8.7A vulnerability has been found in D-Link DIR-823X 240126/240802 and classified as critical. Affected by this vulnerabili...
CVE-2025-0490HIGH8.8A vulnerability, which was classified as critical, has been found in Fanli2012 native-php-cms 1.0. This issue affects so...
CVE-2025-0489HIGH8.8A vulnerability classified as critical was found in Fanli2012 native-php-cms 1.0. This vulnerability affects unknown cod...
CVE-2025-0488HIGH8.8A vulnerability classified as critical has been found in Fanli2012 native-php-cms 1.0. This affects an unknown part of t...
CVE-2025-0484HIGH7.5A vulnerability was found in Fanli2012 native-php-cms 1.0 and classified as critical. This issue affects some unknown pr...
CVE-2025-0482HIGH7.3A vulnerability, which was classified as critical, was found in Fanli2012 native-php-cms 1.0. This affects an unknown pa...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now