2025 CVE Vulnerabilities
45,212 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32485 | MEDIUM | 4.3 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Bjoern WP Performance Pack wp-performance-pack allows Cross Site Requ... |
| CVE-2025-32483 | MEDIUM | 5.9 | 0.3% | Apr 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Salisbury Re... |
| CVE-2025-31042 | MEDIUM | 5.3 | 0.4% | Apr 9, 2025 | Missing Authorization vulnerability in rtakao Sandwich Adsense firsth3tagadsense allows Exploiting Incorrectly Configure... |
| CVE-2025-31035 | MEDIUM | 5.9 | 0.3% | Apr 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Chris WP ... |
| CVE-2025-31034 | MEDIUM | 4.3 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in AboZain Albanna Customize Login Page customize-login-page allows Cros... |
| CVE-2025-31020 | MEDIUM | 6.5 | 0.3% | Apr 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webliberty Simple ... |
| CVE-2025-31017 | MEDIUM | 6.5 | 0.3% | Apr 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robert Noakes Nav ... |
| CVE-2025-31012 | MEDIUM | 5.3 | 0.4% | Apr 9, 2025 | Missing Authorization vulnerability in Phil Age Gate age-gate allows Accessing Functionality Not Properly Constrained by... |
| CVE-2025-31009 | MEDIUM | 5.4 | 0.3% | Apr 9, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Jan Boddez IndieBlocks indieblocks allows Server Side Request Forger... |
| CVE-2025-31008 | MEDIUM | 5.9 | 0.3% | Apr 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Embeds For YouTube... |
| CVE-2025-31005 | MEDIUM | 4.3 | 0.2% | Apr 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Uzair Easyfonts easyfonts allows Cross Site Request Forgery.This issu... |
| CVE-2025-31004 | MEDIUM | 4.3 | 0.3% | Apr 9, 2025 | Missing Authorization vulnerability in Croover.inc Rich Table of Contents rich-table-of-content allows Exploiting Incorr... |
| CVE-2025-32381 | MEDIUM | 6.5 | 0.4% | Apr 9, 2025 | XGrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to 0.1.18, Xgramma... |
| CVE-2025-32379 | MEDIUM | 6.1 | 0.2% | Apr 9, 2025 | Koa is expressive middleware for Node.js using ES2017 async functions. In koa < 2.16.1 and < 3.0.0-alpha.5, passing untr... |
| CVE-2025-32378 | MEDIUM | 5.3 | 0.2% | Apr 9, 2025 | Shopware is an open source e-commerce software platform. Prior to 6.6.10.3 or 6.5.8.17, the default settings for double-... |
| CVE-2025-32373 | MEDIUM | 6.5 | 0.3% | Apr 9, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In limited... |
| CVE-2025-32371 | MEDIUM | 4.3 | 0.2% | Apr 9, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A url coul... |
| CVE-2025-32016 | MEDIUM | 4.7 | 0.1% | Apr 9, 2025 | Microsoft Identity Web is a library which contains a set of reusable classes used in conjunction with ASP.NET Core for i... |
| CVE-2025-29389 | MEDIUM | 6.1 | 0.2% | Apr 9, 2025 | PbootCMS v3.2.9 contains a XSS vulnerability in admin.php?p=/Content/index/mcode/2#tab=t2. |
| CVE-2025-27391 | MEDIUM | 6.5 | 0.3% | Apr 9, 2025 | Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker ... |
| CVE-2025-25023 | MEDIUM | 4.9 | 0.3% | Apr 9, 2025 | IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due to incorrect privil... |
| CVE-2025-31672 | MEDIUM | 5.3 | 1.1% | Apr 9, 2025 | Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, do... |
| CVE-2025-30677 | MEDIUM | 6.5 | 0.6% | Apr 9, 2025 | Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connecto... |
| CVE-2025-2442 | MEDIUM | 6.8 | 0.2% | Apr 9, 2025 | CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could potentially lead to unau... |
| CVE-2025-2441 | MEDIUM | 4.6 | 0.2% | Apr 9, 2025 | CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could lead to loss of confiden... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now