2025 CVE Vulnerabilities
45,208 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22983 | HIGH | 7.5 | 0.5% | Jan 14, 2025 | An access control issue in the component /square/getAllSquare/circle of iceCMS v2.2.0 allows unauthenticated attackers t... |
| CVE-2025-0461 | HIGH | 7.5 | 0.8% | Jan 14, 2025 | A vulnerability has been found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0 and classified as ... |
| CVE-2025-0460 | HIGH | 7.3 | 0.4% | Jan 14, 2025 | A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affect... |
| CVE-2025-20620 | HIGH | 7.5 | 0.4% | Jan 14, 2025 | SQL Injection vulnerability exists in STEALTHONE D220/D340 provided by Y'S corporation. An attacker who can access the a... |
| CVE-2025-20016 | HIGH | 7.2 | 1.1% | Jan 14, 2025 | OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340/D440 provided by Y'S corporati... |
| CVE-2025-0394 | HIGH | 8.8 | 1.1% | Jan 14, 2025 | The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulner... |
| CVE-2025-23082 | HIGH | 7.2 | 0.3% | Jan 14, 2025 | Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated ... |
| CVE-2025-0069 | HIGH | 7.8 | 0.2% | Jan 14, 2025 | Due to DLL injection vulnerability in SAPSetup, an attacker with either local user privileges or with access to a compro... |
| CVE-2025-0066 | HIGH | 8.8 | 0.6% | Jan 14, 2025 | Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attack... |
| CVE-2025-0063 | HIGH | 8.8 | 0.7% | Jan 14, 2025 | SAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC function modules.... |
| CVE-2025-22963 | HIGH | 7.5 | 0.3% | Jan 13, 2025 | Teedy through 1.11 allows CSRF for account takeover via POST /api/user/admin. |
| CVE-2025-22800 | HIGH | 8.8 | 0.4% | Jan 13, 2025 | Missing Authorization vulnerability in Saad Iqbal Post SMTP post-smtp allows Exploiting Incorrectly Configured Access Co... |
| CVE-2025-22588 | HIGH | 7.1 | 0.2% | Jan 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in intelligence_lab S... |
| CVE-2025-22586 | HIGH | 7.1 | 0.2% | Jan 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dstoever WPEX Repl... |
| CVE-2025-22583 | HIGH | 7.1 | 0.2% | Jan 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in anshulsojatia Scan... |
| CVE-2025-22576 | HIGH | 7.1 | 0.3% | Jan 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Downing Sit... |
| CVE-2025-22570 | HIGH | 7.1 | 0.3% | Jan 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mdjekic Inline Twe... |
| CVE-2025-22569 | HIGH | 7.1 | 0.2% | Jan 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GrandSlambert Feat... |
| CVE-2025-22568 | HIGH | 7.1 | 0.3% | Jan 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arete-it Post And ... |
| CVE-2025-22567 | HIGH | 7.1 | 0.2% | Jan 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in trustist TRUSTist ... |
| CVE-2025-22514 | HIGH | 7.1 | 0.3% | Jan 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yamna Khawaja KNR ... |
| CVE-2025-22506 | HIGH | 7.1 | 0.2% | Jan 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Smart Agenda Smart... |
| CVE-2025-22499 | HIGH | 7.1 | 0.2% | Jan 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FAKTOR VIER F4 Pos... |
| CVE-2025-22498 | HIGH | 7.1 | 0.2% | Jan 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N3wNormal LucidLMS... |
| CVE-2025-22344 | HIGH | 7.1 | 0.2% | Jan 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in timmcdaniels Media... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now