2025 CVE Vulnerabilities
45,221 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32161 | MEDIUM | 6.5 | 0.3% | Apr 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryo Arkhe Blocks a... |
| CVE-2025-32138 | MEDIUM | 6.6 | 0.5% | Apr 4, 2025 | Improper Restriction of XML External Entity Reference vulnerability in supsystic Easy Google Maps google-maps-easy allow... |
| CVE-2025-32137 | MEDIUM | 4.9 | 0.7% | Apr 4, 2025 | Relative Path Traversal vulnerability in Cristián Lávaque s2Member s2member allows Path Traversal.This issue affects s2M... |
| CVE-2025-32136 | MEDIUM | 5.9 | 0.4% | Apr 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in activecampaign Act... |
| CVE-2025-32135 | MEDIUM | 5.9 | 0.4% | Apr 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rocketelements Spl... |
| CVE-2025-32134 | MEDIUM | 5.9 | 0.4% | Apr 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders URL S... |
| CVE-2025-32133 | MEDIUM | 5.9 | 0.4% | Apr 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Secure Cop... |
| CVE-2025-32132 | MEDIUM | 5.9 | 0.4% | Apr 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelCockpit Funn... |
| CVE-2025-32131 | MEDIUM | 5.9 | 0.4% | Apr 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in socialintents Soci... |
| CVE-2025-32130 | MEDIUM | 5.9 | 0.4% | Apr 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Risk Mitig... |
| CVE-2025-32129 | MEDIUM | 5.9 | 0.4% | Apr 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Risk Mitig... |
| CVE-2025-3251 | MEDIUM | 6.1 | 0.3% | Apr 4, 2025 | A vulnerability, which was classified as problematic, was found in xujiangfei admintwo 1.0. This affects an unknown part... |
| CVE-2025-3250 | MEDIUM | 6.5 | 0.4% | Apr 4, 2025 | A vulnerability, which was classified as problematic, has been found in elunez eladmin 2.7. Affected by this issue is so... |
| CVE-2025-31130 | MEDIUM | 6.8 | 0.2% | Apr 4, 2025 | gitoxide is an implementation of git written in Rust. Before 0.42.0, gitoxide uses SHA-1 hash implementations without an... |
| CVE-2025-31407 | MEDIUM | 6.5 | 0.2% | Apr 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hutsixdigital Tige... |
| CVE-2025-31381 | MEDIUM | 6.5 | 0.3% | Apr 4, 2025 | Missing Authorization vulnerability in shiptrack Booking Calendar and Notification booking-calendar-and-notification all... |
| CVE-2025-22285 | MEDIUM | 6.5 | 0.3% | Apr 4, 2025 | Missing Authorization vulnerability in enituretechnology Pallet Packaging for WooCommerce pallet-packaging-for-woocommer... |
| CVE-2025-22281 | MEDIUM | 6.5 | 0.2% | Apr 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in joshix Simplish si... |
| CVE-2025-3189 | MEDIUM | 4.8 | 0.3% | Apr 4, 2025 | Stored Cross-Site Scripting (XSS) in DoWISP in versions prior to 1.16.2.50, which consists of an stored XSS through the ... |
| CVE-2025-31421 | MEDIUM | 5.8 | 0.3% | Apr 4, 2025 | Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Oblak Studio Srbtransla... |
| CVE-2025-3237 | MEDIUM | 6.9 | 0.5% | Apr 4, 2025 | A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue affects some unknown ... |
| CVE-2025-3236 | MEDIUM | 6.9 | 0.6% | Apr 4, 2025 | A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vulnerability affects un... |
| CVE-2025-2245 | MEDIUM | 5.3 | 0.3% | Apr 4, 2025 | A server-side request forgery (SSRF) vulnerability exists in the Bitdefender GravityZone Update Server when operating in... |
| CVE-2025-3219 | MEDIUM | 5.4 | 0.3% | Apr 4, 2025 | A vulnerability was found in CodeCanyon Perfex CRM 3.2.1. It has been classified as problematic. Affected is an unknown ... |
| CVE-2025-3087 | MEDIUM | 5.4 | 0.2% | Apr 4, 2025 | Stored XSS in M-Files Web versions from 25.1.14445.5 to 25.2.14524.4 allows an authenticated user to run scripts |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now