2025 CVE Vulnerabilities

45,208 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-22983HIGH7.5An access control issue in the component /square/getAllSquare/circle of iceCMS v2.2.0 allows unauthenticated attackers t...
CVE-2025-0461HIGH7.5A vulnerability has been found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0 and classified as ...
CVE-2025-0460HIGH7.3A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affect...
CVE-2025-20620HIGH7.5SQL Injection vulnerability exists in STEALTHONE D220/D340 provided by Y'S corporation. An attacker who can access the a...
CVE-2025-20016HIGH7.2OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340/D440 provided by Y'S corporati...
CVE-2025-0394HIGH8.8The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulner...
CVE-2025-23082HIGH7.2Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated ...
CVE-2025-0069HIGH7.8Due to DLL injection vulnerability in SAPSetup, an attacker with either local user privileges or with access to a compro...
CVE-2025-0066HIGH8.8Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attack...
CVE-2025-0063HIGH8.8SAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC function modules....
CVE-2025-22963HIGH7.5Teedy through 1.11 allows CSRF for account takeover via POST /api/user/admin.
CVE-2025-22800HIGH8.8Missing Authorization vulnerability in Saad Iqbal Post SMTP post-smtp allows Exploiting Incorrectly Configured Access Co...
CVE-2025-22588HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in intelligence_lab S...
CVE-2025-22586HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dstoever WPEX Repl...
CVE-2025-22583HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in anshulsojatia Scan...
CVE-2025-22576HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Downing Sit...
CVE-2025-22570HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mdjekic Inline Twe...
CVE-2025-22569HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GrandSlambert Feat...
CVE-2025-22568HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arete-it Post And ...
CVE-2025-22567HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in trustist TRUSTist ...
CVE-2025-22514HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yamna Khawaja KNR ...
CVE-2025-22506HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Smart Agenda Smart...
CVE-2025-22499HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FAKTOR VIER F4 Pos...
CVE-2025-22498HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N3wNormal LucidLMS...
CVE-2025-22344HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in timmcdaniels Media...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now