2025 CVE Vulnerabilities

45,209 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-22520HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Tock Tock Widget tock-widget allows Cross Site Request Forgery.This i...
CVE-2025-22519HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jerodmoore eDoc Ea...
CVE-2025-22507HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in iDo8p WPMU Prefill...
CVE-2025-22502HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mindvalley MindVal...
CVE-2025-22338HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lich_wang WP-tagMa...
CVE-2025-22335HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rajib.dewan Openca...
CVE-2025-22294HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in theme funda Custom...
CVE-2025-21623HIGH7.5ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 238, ClipBucket V5 allows unauthenticated at...
CVE-2025-0241HIGH7.7When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially exploitable crash. Th...
CVE-2025-0294HIGH8.8A vulnerability has been found in SourceCodester Home Clean Services Management System 1.0 and classified as critical. A...
CVE-2025-22364HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-22359HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pjfc SyncFields sy...
CVE-2025-22358HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simone Marcon Wp a...
CVE-2025-22357HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdever Target Not...
CVE-2025-22355HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in asokaaso2 Kikx Sim...
CVE-2025-22353HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bvads BVD Easy Gal...
CVE-2025-22352HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX ...
CVE-2025-22351HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in penguinarts Contac...
CVE-2025-22349HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Marka WordPress...
CVE-2025-22348HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in rtowebsites Dynami...
CVE-2025-22347HIGH8.2Cross-Site Request Forgery (CSRF) vulnerability in bannersky BSK Forms Blacklist bsk-gravityforms-blacklist allows Blind...
CVE-2025-22343HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in koter84 wpSOL wpsol allows Stored XSS.This issue affects wpSOL: from ...
CVE-2025-22342HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Jenst WP Simple Sitemap wp-simple-sitemap allows Stored XSS.This issu...
CVE-2025-22336HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Amos Lee(一刀) Wizhi Multi Filters by Wenprise wizhi-multi-filters allo...
CVE-2025-22328HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Elevio by Dixa Elevio elevio allows Stored XSS.This issue affects Ele...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now