2025 CVE Vulnerabilities
45,209 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22595 | HIGH | 7.1 | 0.3% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yamna Khawaja Mail... |
| CVE-2025-22594 | HIGH | 7.1 | 0.3% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hccoder Better Use... |
| CVE-2025-22539 | HIGH | 7.1 | 0.3% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ka2 Custom DataBas... |
| CVE-2025-22537 | HIGH | 8.5 | 0.4% | Jan 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in traveller11 Google... |
| CVE-2025-22535 | HIGH | 8.5 | 0.4% | Jan 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jonkern WPListCal ... |
| CVE-2025-22527 | HIGH | 7.6 | 0.5% | Jan 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yamna Khawaja Mail... |
| CVE-2025-22521 | HIGH | 7.1 | 0.3% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Farrell wp H... |
| CVE-2025-22510 | HIGH | 7.2 | 1.2% | Jan 9, 2025 | Deserialization of Untrusted Data vulnerability in kkarpieszuk WC Price History for Omnibus wc-price-history allows Obje... |
| CVE-2025-22508 | HIGH | 8.1 | 0.7% | Jan 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-22505 | HIGH | 8.5 | 0.4% | Jan 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crispweb NC Wishli... |
| CVE-2025-22361 | HIGH | 7.1 | 0.3% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Opentracker Opentr... |
| CVE-2025-22345 | HIGH | 7.1 | 0.3% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tsinf TS Comfort D... |
| CVE-2025-22331 | HIGH | 7.1 | 0.3% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in P3JX Cf7Save Exten... |
| CVE-2025-22330 | HIGH | 7.1 | 0.3% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mahesh Waghmare MG... |
| CVE-2025-22313 | HIGH | 7.1 | 0.3% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Widgetiz... |
| CVE-2025-22307 | HIGH | 7.1 | 0.3% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saiful Islam Produ... |
| CVE-2025-22295 | HIGH | 7.1 | 0.4% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tripetto WordPress... |
| CVE-2025-0346 | HIGH | 7.2 | 0.5% | Jan 9, 2025 | A vulnerability was found in code-projects Content Management System 1.0. It has been classified as critical. This affec... |
| CVE-2025-0345 | HIGH | 8.8 | 0.5% | Jan 9, 2025 | A vulnerability was found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this issue is the function list... |
| CVE-2025-0344 | HIGH | 8.8 | 0.5% | Jan 9, 2025 | A vulnerability has been found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this vulnerability is the ... |
| CVE-2025-0334 | HIGH | 8.8 | 0.5% | Jan 9, 2025 | A vulnerability has been found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this vulnerability is the ... |
| CVE-2025-0333 | HIGH | 8.8 | 0.6% | Jan 9, 2025 | A vulnerability, which was classified as critical, was found in leiyuxi cy-fast 1.0. Affected is the function listData o... |
| CVE-2025-0328 | HIGH | 7.3 | 2.2% | Jan 9, 2025 | A vulnerability, which was classified as critical, has been found in KaiYuanTong ECT Platform up to 2.0.0. Affected by t... |
| CVE-2025-0306 | HIGH | 7.4 | 0.6% | Jan 9, 2025 | A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attac... |
| CVE-2025-0283 | HIGH | 7 | 17.1% | Jan 8, 2025 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now