2025 CVE Vulnerabilities
45,207 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0501 | HIGH | 7.7 | 0.4% | Jan 15, 2025 | An issue in the native clients for Amazon WorkSpaces (when running PCoIP protocol) may allow an attacker to access remot... |
| CVE-2025-0500 | HIGH | 7.7 | 0.5% | Jan 15, 2025 | An issue in the native clients for Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazo... |
| CVE-2025-0481 | HIGH | 7.5 | 1.4% | Jan 15, 2025 | A vulnerability classified as problematic has been found in D-Link DIR-878 1.03. Affected is an unknown function of the ... |
| CVE-2025-22799 | HIGH | 8.5 | 0.4% | Jan 15, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vertim Neon Produc... |
| CVE-2025-22795 | HIGH | 7.1 | 0.3% | Jan 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitaldonkey Mult... |
| CVE-2025-22793 | HIGH | 7.1 | 0.3% | Jan 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bold Bold pagos en... |
| CVE-2025-22787 | HIGH | 8.8 | 0.3% | Jan 15, 2025 | Missing Authorization vulnerability in bPlugins Button Block button-block allows Accessing Functionality Not Properly Co... |
| CVE-2025-22786 | HIGH | 8.8 | 0.7% | Jan 15, 2025 | Path Traversal: '.../...//' vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-f... |
| CVE-2025-22784 | HIGH | 8.6 | 0.3% | Jan 15, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in swedish boy Background Control background-control allows Path Travers... |
| CVE-2025-22778 | HIGH | 7.1 | 0.3% | Jan 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in damniel Lijit Sear... |
| CVE-2025-22776 | HIGH | 7.1 | 0.3% | Jan 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codebycarter WP Bu... |
| CVE-2025-22766 | HIGH | 7.1 | 0.3% | Jan 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Masoud Amini Zarin... |
| CVE-2025-22765 | HIGH | 7.1 | 0.3% | Jan 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weiluri WP Order B... |
| CVE-2025-22764 | HIGH | 7.1 | 0.3% | Jan 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vipul Jariwala WP ... |
| CVE-2025-22755 | HIGH | 7.1 | 0.3% | Jan 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bavington WP Headm... |
| CVE-2025-22754 | HIGH | 7.1 | 0.3% | Jan 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Berkman Klein Cent... |
| CVE-2025-22753 | HIGH | 7.1 | 0.3% | Jan 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in turboSMTP turboSMT... |
| CVE-2025-22751 | HIGH | 7.1 | 0.3% | Jan 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in farinspace Partner... |
| CVE-2025-22750 | HIGH | 7.1 | 0.3% | Jan 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Patel Post Carouse... |
| CVE-2025-22736 | HIGH | 8.8 | 0.4% | Jan 15, 2025 | Incorrect Privilege Assignment vulnerability in Saad Iqbal User Management user-management allows Privilege Escalation.T... |
| CVE-2025-22317 | HIGH | 7.1 | 0.3% | Jan 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gallery Ape Photo ... |
| CVE-2025-0447 | HIGH | 8.8 | 0.4% | Jan 15, 2025 | Inappropriate implementation in Navigation in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to perform ... |
| CVE-2025-0443 | HIGH | 8.8 | 0.4% | Jan 15, 2025 | Insufficient data validation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinc... |
| CVE-2025-0438 | HIGH | 8.8 | 0.5% | Jan 15, 2025 | Stack buffer overflow in Tracing in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploi... |
| CVE-2025-0437 | HIGH | 8.8 | 0.3% | Jan 15, 2025 | Out of bounds read in Metrics in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit h... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now